2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-76702MEDIUM5.8A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local...
CVE-2026-76701MEDIUM5.9A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote ...
CVE-2026-76700MEDIUM5.9Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a ...
CVE-2026-76699MEDIUM6.4A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking Edge...
CVE-2026-76698MEDIUM6.5A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gate...
CVE-2026-76697MEDIUM6.5A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote...
CVE-2026-76696MEDIUM6.5A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduc...
CVE-2026-76695MEDIUM6.5Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways t...
CVE-2026-76694MEDIUM6.6A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways....
CVE-2026-73965MEDIUM6.8Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Cloud Gateway). Supported versions ...
CVE-2026-70755MEDIUM6.5Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File down...
CVE-2026-69215MEDIUM6.8Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unan...
CVE-2026-69206MEDIUM5.9Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records last...
CVE-2026-62597MEDIUM6.5Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana...
CVE-2026-51133MEDIUM6.1Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to e...
CVE-2026-32599MEDIUM5.3Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database...
CVE-2026-18422MEDIUM6.5Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in th...
CVE-2026-90971MEDIUM6.5Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier all...
CVE-2026-90969MEDIUM6.5Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authent...
CVE-2026-84850MEDIUM4.8Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolution...
CVE-2026-84048MEDIUM6.3Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < ...
CVE-2026-82191MEDIUM5.3Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2,...
CVE-2026-82190MEDIUM6.3Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0...
CVE-2026-81924MEDIUM6.5Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation featu...
CVE-2026-81921MEDIUM5.4Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, w...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now