2026 CVE Vulnerabilities

51,327 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-23249MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: check for deleted cursors when revalidating tw...
CVE-2026-30695MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access con...
CVE-2026-33004MEDIUM4.3Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, incre...
CVE-2026-33003MEDIUM4.3Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins co...
CVE-2026-2559MEDIUM5.3The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2026-2512MEDIUM6.4The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all ver...
CVE-2026-3278MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks...
CVE-2026-32694MEDIUM6.6In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret o...
CVE-2026-32692MEDIUM6.5An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18...
CVE-2026-32691MEDIUM5.3A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit ...
CVE-2026-23247MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This ...
CVE-2026-32565MEDIUM5.3Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrec...
CVE-2026-1217MEDIUM5.4The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2026-22321MEDIUM5.3A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send a...
CVE-2026-22320MEDIUM6.5A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel...
CVE-2026-22319MEDIUM4.9A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send overs...
CVE-2026-22318MEDIUM4.9A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged at...
CVE-2026-22316MEDIUM6.5A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to tri...
CVE-2026-3512MEDIUM6.1The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter...
CVE-2026-4366MEDIUM5.8A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect...
CVE-2026-33058MEDIUM6.5Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ...
CVE-2026-32265MEDIUM6.9The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una...
CVE-2026-31938MEDIUM6.1jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the...
CVE-2026-31898MEDIUM6.5jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot...
CVE-2026-31891MEDIUM6.5Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now