2026 CVE Vulnerabilities

50,391 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2400MEDIUM4.3CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application us...
CVE-2026-2399MEDIUM6.1CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could ca...
CVE-2026-25691MEDIUM6.7A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ...
CVE-2026-22576MEDIUM6.5A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS...
CVE-2026-22574MEDIUM6.5A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS...
CVE-2026-22573MEDIUM6.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR Pa...
CVE-2026-22154MEDIUM5.4An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS...
CVE-2026-21742MEDIUM6.5A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA...
CVE-2026-21741MEDIUM4.8An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6....
CVE-2026-4914MEDIUM5.4Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information f...
CVE-2026-4913MEDIUM5.7Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker t...
CVE-2026-37980MEDIUM4.8A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-real...
CVE-2026-30480MEDIUM6.5A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows ...
CVE-2026-24069MEDIUM5.4Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to conti...
CVE-2026-4109MEDIUM4.3The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to u...
CVE-2026-33929MEDIUM4.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. ...
CVE-2026-31924MEDIUM5.3Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plain...
CVE-2026-2582MEDIUM6.5The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_hold...
CVE-2026-4479MEDIUM4.4The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-4059MEDIUM6.4The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shor...
CVE-2026-1607MEDIUM6.4The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `s...
CVE-2026-34984MEDIUM6.5External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-39426MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS...
CVE-2026-39425MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS...
CVE-2026-34225MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and be...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now