2026 CVE Vulnerabilities

50,971 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-23419MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/rds: Fix circular locking dependency in rds_tcp...
CVE-2026-23418MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe/reg_sr: Fix leak on xa_store failure Free t...
CVE-2026-27655MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on M...
CVE-2026-5467MEDIUM6.1A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component...
CVE-2026-4108MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Perm...
CVE-2026-4107MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count a...
CVE-2026-3880MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client P...
CVE-2026-3879MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Deta...
CVE-2026-28703MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Betwee...
CVE-2026-28756MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on D...
CVE-2026-28754MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists rep...
CVE-2026-35549MEDIUM6.5An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. I...
CVE-2026-35544MEDIUM5.3An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitiz...
CVE-2026-35543MEDIUM5.3An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed...
CVE-2026-35542MEDIUM5.3An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed...
CVE-2026-35541MEDIUM4.2An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plu...
CVE-2026-35540MEDIUM6.5An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization...
CVE-2026-35539MEDIUM6.1An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachmen...
CVE-2026-35536MEDIUM5.3In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .Req...
CVE-2026-35508MEDIUM6.1Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters,
CVE-2026-35507MEDIUM6.5Shynet before 0.14.0 allows Host header injection in the password reset flow.
CVE-2026-35466MEDIUM6.1XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from C...
CVE-2026-30252MEDIUM6.1Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l Zen...
CVE-2026-30251MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenSh...
CVE-2026-35383MEDIUM6.9Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated att...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now