2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12697MEDIUM5.4The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us...
CVE-2026-12376MEDIUM4.3The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing...
CVE-2026-63220MEDIUM4.8CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For...
CVE-2026-62323MEDIUM6.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the se...
CVE-2026-55499MEDIUM4.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscri...
CVE-2026-55497MEDIUM6.5Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image ...
CVE-2026-55496MEDIUM4.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActi...
CVE-2026-55495MEDIUM4.3Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-W...
CVE-2026-43833MEDIUM5.3Full details and mitigation steps are currently restricted and will be published at a later date.
CVE-2026-14540MEDIUM6.1A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-t...
CVE-2026-66349MEDIUM6.9The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed ...
CVE-2026-63033MEDIUM6.9A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationO...
CVE-2026-61893MEDIUM6.9A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBu...
CVE-2026-56758MEDIUM6.9The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain...
CVE-2026-10031MEDIUM4.2SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-direc...
CVE-2026-68563MEDIUM5.5A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and th...
CVE-2026-68562MEDIUM6.2A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp ...
CVE-2026-62845MEDIUM4.7Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv...
CVE-2026-68501MEDIUM6.5Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli...
CVE-2026-68499MEDIUM6.2re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match ...
CVE-2026-61526MEDIUM6.1AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through...
CVE-2026-55777MEDIUM5.3GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b...
CVE-2026-67550MEDIUM5.7re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex again...
CVE-2026-67530MEDIUM6.4WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/...
CVE-2026-67529MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /ap...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now