2026 CVE Vulnerabilities

50,301 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-20132MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au...
CVE-2026-20081MEDIUM6.5Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr...
CVE-2026-20078MEDIUM6.5Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr...
CVE-2026-20061MEDIUM6.5A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att...
CVE-2026-20060MEDIUM4.7A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2026-20059MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2026-20203MEDIUM4.3In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-20202MEDIUM6.6In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-4135MEDIUM6.6During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins...
CVE-2026-25219MEDIUM6.5The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. Thi...
CVE-2026-1636MEDIUM6.7A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allo...
CVE-2026-3590MEDIUM6.5Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin...
CVE-2026-1852MEDIUM6.1The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2026-40786MEDIUM4.3Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured A...
CVE-2026-40778MEDIUM5.3Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly ...
CVE-2026-40763MEDIUM5.3Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrec...
CVE-2026-40742MEDIUM5.3Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Co...
CVE-2026-40740MEDIUM5.4Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-40737MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exp...
CVE-2026-40734MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories ...
CVE-2026-40730MEDIUM5.3Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting In...
CVE-2026-40729MEDIUM4.3Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Conf...
CVE-2026-40728MEDIUM4.3Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured...
CVE-2026-0636MEDIUM6.5Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Boun...
CVE-2026-5717MEDIUM6.4The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now