2026 CVE Vulnerabilities

50,981 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-21631MEDIUM5.4Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-1879MEDIUM6.3A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the fil...
CVE-2026-34889MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force U...
CVE-2026-23409MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: apparmor: fix differential encoding verification D...
CVE-2026-23405MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: apparmor: fix: limit the number of levels of policy...
CVE-2026-23404MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: apparmor: replace recursive profile removal with it...
CVE-2026-23403MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: apparmor: fix memory leak in verify_header The fun...
CVE-2026-23402MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Only WARN in direct MMUs when overwri...
CVE-2026-23401MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Drop/zap existing present SPTE even w...
CVE-2026-5259MEDIUM6.3A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the...
CVE-2026-5255MEDIUM6.1A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delst...
CVE-2026-2696MEDIUM5.3The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) ...
CVE-2026-5291MEDIUM6.5Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain poten...
CVE-2026-5283MEDIUM6.5Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-o...
CVE-2026-5276MEDIUM6.5Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain p...
CVE-2026-5273MEDIUM6.3Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code insid...
CVE-2026-5251MEDIUM6.3A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user...
CVE-2026-3831MEDIUM4.3The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of d...
CVE-2026-3778MEDIUM5.5The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pag...
CVE-2026-3776MEDIUM5.5The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resour...
CVE-2026-5248MEDIUM6.3A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app...
CVE-2026-35057MEDIUM5.4XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, ...
CVE-2026-35055MEDIUM6.1XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. A...
CVE-2026-35054MEDIUM5.4XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can in...
CVE-2026-2394MEDIUM6.5Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects C...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now