2026 CVE Vulnerabilities

50,974 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-32629MEDIUM6.1phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest F...
CVE-2026-5332MEDIUM6.1A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of t...
CVE-2026-30867MEDIUM6.5CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exist...
CVE-2026-2737MEDIUM6.1A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a ma...
CVE-2026-26927MEDIUM5.1Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched...
CVE-2026-5331MEDIUM4.7A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the compon...
CVE-2026-5330MEDIUM6.5A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some ...
CVE-2026-5328MEDIUM6.3A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted e...
CVE-2026-4325MEDIUM5.3A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso...
CVE-2026-34890MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MST...
CVE-2026-5327MEDIUM6.3A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function h...
CVE-2026-23417MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores ...
CVE-2026-23416MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/mseal: update VMA end correctly on merge Previo...
CVE-2026-23414MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() ...
CVE-2026-5326MEDIUM5.5A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the fi...
CVE-2026-33617MEDIUM5.3An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a...
CVE-2026-29144MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security...
CVE-2026-29142MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.
CVE-2026-29141MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags suc...
CVE-2026-29140MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be u...
CVE-2026-29137MEDIUM5.3SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a lo...
CVE-2026-29136MEDIUM6.1SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new...
CVE-2026-0688MEDIUM6.4The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5...
CVE-2026-5323MEDIUM5.3A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the ...
CVE-2026-5321MEDIUM4.3A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the compone...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now