2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-86522MEDIUM6.3Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attack...
CVE-2026-81829MEDIUM5.3A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by ...
CVE-2026-81453MEDIUM6.5Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Res...
CVE-2026-81443MEDIUM6.4Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerab...
CVE-2026-80355MEDIUM5.4Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerabi...
CVE-2026-78528MEDIUM5.3Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.
CVE-2026-78294MEDIUM6.5Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
CVE-2026-78223MEDIUM6.9Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the ...
CVE-2026-74017MEDIUM5.3Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.
CVE-2026-74005MEDIUM5.4Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.
CVE-2026-74002MEDIUM5.3Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
CVE-2026-74000MEDIUM5.3Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
CVE-2026-73999MEDIUM5.4Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
CVE-2026-71568MEDIUM5.3In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requir...
CVE-2026-66676MEDIUM5.3Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
CVE-2026-66617MEDIUM6.5Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
CVE-2026-66608MEDIUM6.4Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= ...
CVE-2026-66579MEDIUM6.5Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
CVE-2026-66578MEDIUM6.5Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
CVE-2026-66577MEDIUM6.5Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
CVE-2026-66576MEDIUM6.5Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
CVE-2026-66575MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.
CVE-2026-66574MEDIUM6.5Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
CVE-2026-66573MEDIUM6.5Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.
CVE-2026-66572MEDIUM6.5Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now