2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-67335MEDIUM6better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-...
CVE-2026-67334MEDIUM5.1better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp...
CVE-2026-67332MEDIUM6.4@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing...
CVE-2026-67321MEDIUM6.9axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js w...
CVE-2026-67319MEDIUM6.3axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the...
CVE-2026-67318MEDIUM6.3axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bo...
CVE-2026-67317MEDIUM6.3axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch a...
CVE-2026-67316MEDIUM6.3axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype h...
CVE-2026-67315MEDIUM6.9axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBy...
CVE-2026-67314MEDIUM6.3axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/a...
CVE-2026-67313MEDIUM6.3axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names wi...
CVE-2026-67312MEDIUM6.3axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (...
CVE-2026-67310MEDIUM5.4OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in t...
CVE-2026-67306MEDIUM5.4FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder fu...
CVE-2026-67303MEDIUM5.3FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_proce...
CVE-2026-67302MEDIUM5.3FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redire...
CVE-2026-67295MEDIUM6.3FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to...
CVE-2026-2411MEDIUM6.5Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose...
CVE-2026-10773MEDIUM5.4The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const c...
CVE-2026-6453MEDIUM6.5The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi...
CVE-2026-18435MEDIUM6.4The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-18344MEDIUM6.1The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par...
CVE-2026-18062MEDIUM6.4The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-18059MEDIUM5.3The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp...
CVE-2026-17605MEDIUM6.6The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Incl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now