2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-92616MEDIUM6.8FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege att...
CVE-2026-92570MEDIUM6.5reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any...
CVE-2026-92569MEDIUM4.3Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that f...
CVE-2026-92568MEDIUM5.4MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows...
CVE-2026-92567MEDIUM6.5TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update ...
CVE-2026-92565MEDIUM5.3Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns sched...
CVE-2026-92383MEDIUM4.3A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserControl...
CVE-2026-89031MEDIUM5.4Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records o...
CVE-2026-88976MEDIUM6.1Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0....
CVE-2026-84859MEDIUM6.5ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search e...
CVE-2026-77401MEDIUM6.8Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untruste...
CVE-2026-77119MEDIUM5.9A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure deleg...
CVE-2026-75029MEDIUM5.3In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SO...
CVE-2026-61709MEDIUM5.3OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return ...
CVE-2026-19668MEDIUM5.3A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular k...
CVE-2026-19033MEDIUM6.5For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer ...
CVE-2026-92468MEDIUM6.5zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service...
CVE-2026-92365MEDIUM4.3A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the...
CVE-2026-92364MEDIUM6.3A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown...
CVE-2026-92363MEDIUM4.3A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp...
CVE-2026-92141MEDIUM4.3Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attack...
CVE-2026-92140MEDIUM6.8Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in ...
CVE-2026-92139MEDIUM6.5Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, includin...
CVE-2026-92138MEDIUM4.2The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callb...
CVE-2026-92133MEDIUM5.4Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now