2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-18321MEDIUM4.7Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
CVE-2026-34497MEDIUM5.4Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste...
CVE-2026-34495MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F...
CVE-2026-34490MEDIUM5.5Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac...
CVE-2026-58047MEDIUM5.6HTTP Smuggling in cPanel allows potential leak of credentials.
CVE-2026-54707MEDIUM5.4OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien...
CVE-2026-54706MEDIUM4.8OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien...
CVE-2026-59232MEDIUM5.3Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding ...
CVE-2026-59231MEDIUM5.3Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to...
CVE-2026-56571MEDIUM5.3HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions...
CVE-2026-56570MEDIUM5.3HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Va...
CVE-2026-56568MEDIUM5.3HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It inv...
CVE-2026-52857MEDIUM5.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, un...
CVE-2026-17350MEDIUM5.4The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce...
CVE-2026-17348MEDIUM6.9In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's bef...
CVE-2026-67350MEDIUM4.3Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to re...
CVE-2026-28145MEDIUM5.3Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User ...
CVE-2026-28144MEDIUM4.3Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensiti...
CVE-2026-15227MEDIUM5.3Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking t...
CVE-2026-46594MEDIUM5.1A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicio...
CVE-2026-64607MEDIUM5.3HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma...
CVE-2026-44615MEDIUM6.5Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi...
CVE-2026-17567MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-18437MEDIUM5.3The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access ...
CVE-2026-18436MEDIUM5.3The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now