2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-3118MEDIUM6.5A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to ...
CVE-2026-26104MEDIUM5.5A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption heade...
CVE-2026-2410MEDIUM4.3The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2026-2367MEDIUM6.4The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-2301MEDIUM4.3The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all ve...
CVE-2026-3171MEDIUM5.4A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by thi...
CVE-2026-2479MEDIUM5The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t...
CVE-2026-3170MEDIUM4.8A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected...
CVE-2026-1614MEDIUM6.4The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-3100MEDIUM6.5The FTP Backup on the ADM will not properly strictly enforce TLS certificate verification while connecting to an FTP ser...
CVE-2026-27645MEDIUM6.1changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, the RSS single-wat...
CVE-2026-27624MEDIUM6.5Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and...
CVE-2026-27746MEDIUM6.1The SPIP jeux plugin versions prior to 4.1.1 contain a reflected cross-site scripting (XSS) vulnerability in the pre_pro...
CVE-2026-27639MEDIUM5.4Mercator is an open source web application designed to enable mapping of information systems. A stored Cross-Site Script...
CVE-2026-27627MEDIUM6.1Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `reada...
CVE-2026-3146MEDIUM5.5A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_he...
CVE-2026-27822MEDIUM5.4RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Script...
CVE-2026-27621MEDIUM5.4TypiCMS is a multilingual content management system based on the Laravel framework. A Stored Cross-Site Scripting (XSS) ...
CVE-2026-27614MEDIUM6.1Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit ev...
CVE-2026-27612MEDIUM6.1Repostat is a React component to fetch and display GitHub repository info. Prior to version 1.0.1, the `RepoCard` compon...
CVE-2026-27611MEDIUM6.5FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when ...
CVE-2026-27610MEDIUM5.3Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha...
CVE-2026-27609MEDIUM6.5Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha...
CVE-2026-25135MEDIUM4.5OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2026-25127MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now