2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27792MEDIUM5.4Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulner...
CVE-2026-27734MEDIUM6.5Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/c...
CVE-2026-26997MEDIUM5.4ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can stor...
CVE-2026-27758MEDIUM6.5SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its man...
CVE-2026-27756MEDIUM6.1SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the...
CVE-2026-27754MEDIUM6.9SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for sessio...
CVE-2026-22716MEDIUM5Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administr...
CVE-2026-27753MEDIUM6.9SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows re...
CVE-2026-24488MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. In versions up ...
CVE-2026-3277MEDIUM6.5The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client s...
CVE-2026-3327MEDIUM4.8Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated use...
CVE-2026-2831MEDIUM4.9The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to, an...
CVE-2026-24351MEDIUM5.4PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can injec...
CVE-2026-24350MEDIUM5.4PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file...
CVE-2026-1434MEDIUM6.1Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opene...
CVE-2026-1305MEDIUM5.3The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and inclu...
CVE-2026-2383MEDIUM6.4The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all ve...
CVE-2026-2362MEDIUM6.4The WP Accessibility plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'alt' attribute...
CVE-2026-0871MEDIUM4.9A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can vi...
CVE-2026-3302MEDIUM6.1A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown f...
CVE-2026-3293MEDIUM5.5A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner ...
CVE-2026-27653MEDIUM6.7The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permission...
CVE-2026-1558MEDIUM5.3The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, ...
CVE-2026-3286MEDIUM4.3A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save ...
CVE-2026-3284MEDIUM5.5A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conver...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now