2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-26934MEDIUM6.5Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-on...
CVE-2026-26227MEDIUM6.3VideoLAN VLC for Android prior to version 3.7.0 contains an authentication bypass in the Remote Access Server feature du...
CVE-2026-23748MEDIUM6.3Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit d7f55b38, contain an out-of-bounds read in LightDB ...
CVE-2026-23747MEDIUM6.3Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit 48f521b, contain a stack-based buffer overflow in P...
CVE-2026-28296MEDIUM4.3A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplyi...
CVE-2026-28295MEDIUM4.3A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrar...
CVE-2026-26228MEDIUM4.9VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server rout...
CVE-2026-26207MEDIUM5.4Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `discourse-policy`...
CVE-2026-26077MEDIUM6.5Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook en...
CVE-2026-2680MEDIUM6.1Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app....
CVE-2026-2679MEDIUM6.1Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolte...
CVE-2026-2678MEDIUM6.1Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', parameter 'name', in 'a3factura...
CVE-2026-2677MEDIUM6.1Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer...
CVE-2026-28132MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in villatheme WooCommerce Ph...
CVE-2026-28131MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-e...
CVE-2026-28083MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome...
CVE-2026-1698MEDIUM6.1A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 throu...
CVE-2026-1697MEDIUM6.5The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in versio...
CVE-2026-1696MEDIUM6.1Some HTTP security headers are not properly set by the web server when sending responses to the client application.
CVE-2026-1695MEDIUM6.1An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of P...
CVE-2026-1694MEDIUM4.3HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of t...
CVE-2026-1692MEDIUM6.1A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebSc...
CVE-2026-2356MEDIUM5.3The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln...
CVE-2026-27974MEDIUM4.8Audiobookshelf is a self-hosted audiobook and podcast server. A cross-site scripting (XSS) vulnerability exists in versi...
CVE-2026-27963MEDIUM4.8Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now