2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-11383MEDIUM5.4IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scri...
CVE-2026-58218MEDIUM5.3A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY ...
CVE-2026-54364MEDIUM6.9CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inj...
CVE-2026-7260MEDIUM5.5Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP ...
CVE-2026-5582MEDIUM4.3The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24...
CVE-2026-18382MEDIUM6.8A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able...
CVE-2026-18369MEDIUM5.8A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns...
CVE-2026-18362MEDIUM5.9The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-fo...
CVE-2026-16971MEDIUM5.9The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force a...
CVE-2026-16970MEDIUM4.2The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Sto...
CVE-2026-44105MEDIUM6.6The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local a...
CVE-2026-44103MEDIUM6.9An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore ...
CVE-2026-44102MEDIUM6.9An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f...
CVE-2026-64635MEDIUM5.3Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an...
CVE-2026-59328MEDIUM4.2Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browse...
CVE-2026-59327MEDIUM4.4Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string...
CVE-2026-58040MEDIUM6.3An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across ident...
CVE-2026-56850MEDIUM4.1A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) cli...
CVE-2026-16531MEDIUM5.3An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a ...
CVE-2026-16530MEDIUM6.5A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in t...
CVE-2026-15382MEDIUM6.5The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce chec...
CVE-2026-15257MEDIUM5.3The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a fr...
CVE-2026-15255MEDIUM5.3The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in ...
CVE-2026-15252MEDIUM5.4The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX han...
CVE-2026-15250MEDIUM5.3The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now