2026 CVE Vulnerabilities

53,133 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2606MEDIUM6.5IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API M...
CVE-2026-1265MEDIUM5.3IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log f...
CVE-2026-0540MEDIUM6.1DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerabi...
CVE-2026-3344MEDIUM4.9A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and...
CVE-2026-3343MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript...
CVE-2026-3351MEDIUM4.3Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, ...
CVE-2026-3455MEDIUM6.1Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() functi...
CVE-2026-20801MEDIUM5.6Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher ...
CVE-2026-1487MEDIUM6.5The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection ...
CVE-2026-1336MEDIUM5.3The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and m...
CVE-2026-2583MEDIUM6.4The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in a...
CVE-2026-2256MEDIUM6.5A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker t...
CVE-2026-27631MEDIUM5.3Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2026-25477MEDIUM6.1AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redire...
CVE-2026-0027MEDIUM6.7In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to...
CVE-2026-0024MEDIUM4In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of m...
CVE-2026-0015MEDIUM6.2In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input vali...
CVE-2026-0014MEDIUM6.2In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input v...
CVE-2026-0012MEDIUM6.2In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in...
CVE-2026-0005MEDIUM6.2In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing lim...
CVE-2026-28401MEDIUM5.4NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, rich text cell content rendered via...
CVE-2026-28398MEDIUM5.4NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, user-controlled content in comments...
CVE-2026-28397MEDIUM5.4NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, comments rendered via v-html withou...
CVE-2026-28396MEDIUM6.5NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not rev...
CVE-2026-28361MEDIUM6.3NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not valid...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now