2026 CVE Vulnerabilities

50,066 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-39845MEDIUM4.1Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr...
CVE-2026-34244MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by...
CVE-2026-33440MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t...
CVE-2026-33220MEDIUM6.8Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo...
CVE-2026-5758MEDIUM6.5JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker ...
CVE-2026-33214MEDIUM4.3Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo...
CVE-2026-6370MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Aj...
CVE-2026-20170MEDIUM6.1A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, ...
CVE-2026-20161MEDIUM5.5A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low ...
CVE-2026-20152MEDIUM5.3A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could all...
CVE-2026-20148MEDIUM4.9A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal a...
CVE-2026-20136MEDIUM6A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI...
CVE-2026-20132MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au...
CVE-2026-20081MEDIUM6.5Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr...
CVE-2026-20078MEDIUM6.5Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr...
CVE-2026-20061MEDIUM6.5A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att...
CVE-2026-20060MEDIUM4.7A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2026-20059MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2026-20203MEDIUM4.3In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-20202MEDIUM6.6In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-4135MEDIUM6.6During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins...
CVE-2026-25219MEDIUM6.5The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. Thi...
CVE-2026-1636MEDIUM6.7A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allo...
CVE-2026-3590MEDIUM6.5Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin...
CVE-2026-1852MEDIUM6.1The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now