2026 CVE Vulnerabilities

50,995 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-26352MEDIUM5.4Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/v...
CVE-2026-5170MEDIUM5.3A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during...
CVE-2026-5123MEDIUM6.3A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/pack...
CVE-2026-30561MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30560MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30559MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30558MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30557MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30556MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-29597MEDIUM6.5DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged us...
CVE-2026-21712MEDIUM6.5A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malform...
CVE-2026-5164MEDIUM5.5A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provid...
CVE-2026-5122MEDIUM6.3A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg...
CVE-2026-30566MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30565MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30564MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30563MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerabi...
CVE-2026-30082MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngE...
CVE-2026-28528MEDIUM4.6BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET...
CVE-2026-28526MEDIUM5.7BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLA...
CVE-2026-4315MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to t...
CVE-2026-4266MEDIUM6.7An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to...
CVE-2026-1612MEDIUM6.9AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket...
CVE-2026-25704MEDIUM5.8A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in  cosmic-greete...
CVE-2026-5107MEDIUM4.2A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now