2026 CVE Vulnerabilities

52,167 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-21668MEDIUM6.5A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup ...
CVE-2026-2987MEDIUM6.1The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions...
CVE-2026-0809MEDIUM6.3Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-F...
CVE-2026-4040MEDIUM5.5A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the c...
CVE-2026-3234MEDIUM4.3A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeen...
CVE-2026-4016MEDIUM5.3A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_proce...
CVE-2026-4015MEDIUM5.3A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/l...
CVE-2026-4013MEDIUM6.3A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unkno...
CVE-2026-3994MEDIUM5.3A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::...
CVE-2026-3993MEDIUM4.3A security vulnerability has been detected in itsourcecode Payroll Management System 1.0. This vulnerability affects unk...
CVE-2026-3992MEDIUM6.3A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file...
CVE-2026-3990MEDIUM4.3A security flaw has been discovered in CesiumGS CesiumJS up to 1.137.0. Affected by this issue is some unknown functiona...
CVE-2026-2687MEDIUM4.3The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could all...
CVE-2026-3982MEDIUM4.3A vulnerability was determined in itsourcecode University Management System 1.0. Affected by this vulnerability is an un...
CVE-2026-3979MEDIUM5.3A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the fil...
CVE-2026-3977MEDIUM6.3A security vulnerability has been detected in projectsend up to r1945. The affected element is an unknown function of th...
CVE-2026-3226MEDIUM4.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized email notification triggering d...
CVE-2026-1878MEDIUM5.4An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privi...
CVE-2026-1182MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.14 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2026-3968MEDIUM6.3A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the...
CVE-2026-3967MEDIUM6.3A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createOb...
CVE-2026-3966MEDIUM6.3A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the fu...
CVE-2026-3965MEDIUM6.3A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file ...
CVE-2026-2808MEDIUM6.8HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when confi...
CVE-2026-3964MEDIUM5.3A weakness has been identified in OpenAkita up to 1.24.3. This impacts the function run of the file src/openakita/tools/...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now