2026 CVE Vulnerabilities

50,981 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-20097MEDIUM6.5A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20096MEDIUM6.5A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20095MEDIUM6.5A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20090MEDIUM4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20089MEDIUM4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20088MEDIUM4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20087MEDIUM4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20085MEDIUM6.1A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to co...
CVE-2026-20042MEDIUM6.5A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encrypt...
CVE-2026-20041MEDIUM6.1A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attac...
CVE-2026-5175MEDIUM5Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti...
CVE-2026-4989MEDIUM4.3Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticate...
CVE-2026-4927MEDIUM6.5Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privi...
CVE-2026-4925MEDIUM5Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra...
CVE-2026-4829MEDIUM5.4Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an ...
CVE-2026-34510MEDIUM6.9OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file...
CVE-2026-30526MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerabil...
CVE-2026-30523MEDIUM6.5A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input vali...
CVE-2026-29598MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora...
CVE-2026-3877MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution a...
CVE-2026-35094MEDIUM5.5A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can expl...
CVE-2026-34999MEDIUM6.9OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that al...
CVE-2026-30522MEDIUM6.5A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validati...
CVE-2026-25601MEDIUM6.7A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contai...
CVE-2026-21632MEDIUM5.4Lack of output escaping for article titles leads to XSS vectors in various locations.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now