2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-92132MEDIUM5.4Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected i...
CVE-2026-92131MEDIUM4.2Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to ...
CVE-2026-89030MEDIUM4.3Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to l...
CVE-2026-89029MEDIUM4.3Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. ...
CVE-2026-85104MEDIUM5.3In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation...
CVE-2026-78301MEDIUM5.8A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker in...
CVE-2026-56719MEDIUM6.5MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unaut...
CVE-2026-19941MEDIUM5.9An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an...
CVE-2026-19662MEDIUM5.9An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send m...
CVE-2026-92361MEDIUM4.3A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdk...
CVE-2026-92360MEDIUM6.3A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of...
CVE-2026-73169MEDIUM6.3Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scrip...
CVE-2026-92463MEDIUM6.5yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @Pre...
CVE-2026-92462MEDIUM6.5yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing...
CVE-2026-92461MEDIUM4.3yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoin...
CVE-2026-92460MEDIUM6.5yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any ...
CVE-2026-92459MEDIUM6.5yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoin...
CVE-2026-92458MEDIUM4.3yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that...
CVE-2026-92457MEDIUM6.5yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint...
CVE-2026-92455MEDIUM4.3yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, a...
CVE-2026-92357MEDIUM4.3A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-proce...
CVE-2026-92356MEDIUM4.3A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the f...
CVE-2026-86107MEDIUM5.9The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments betwee...
CVE-2026-86443MEDIUM6.9Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an ...
CVE-2026-84501MEDIUM5.3An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a cra...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now