2026 CVE Vulnerabilities

50,196 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-34244MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by...
CVE-2026-33440MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t...
CVE-2026-33220MEDIUM6.8Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo...
CVE-2026-5758MEDIUM6.5JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker ...
CVE-2026-33214MEDIUM4.3Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo...
CVE-2026-6370MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Aj...
CVE-2026-20170MEDIUM6.1A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, ...
CVE-2026-20161MEDIUM5.5A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low ...
CVE-2026-20152MEDIUM5.3A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could all...
CVE-2026-20148MEDIUM4.9A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal a...
CVE-2026-20136MEDIUM6A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI...
CVE-2026-20132MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au...
CVE-2026-20081MEDIUM6.5Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr...
CVE-2026-20078MEDIUM6.5Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr...
CVE-2026-20061MEDIUM6.5A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att...
CVE-2026-20060MEDIUM4.7A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2026-20059MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2026-20203MEDIUM4.3In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-20202MEDIUM6.6In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-4135MEDIUM6.6During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins...
CVE-2026-25219MEDIUM6.5The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. Thi...
CVE-2026-1636MEDIUM6.7A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allo...
CVE-2026-3590MEDIUM6.5Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin...
CVE-2026-1852MEDIUM6.1The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2026-40786MEDIUM4.3Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured A...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now