2026 CVE Vulnerabilities

53,163 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27503MEDIUM6.1SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in admin/log.php via the search q...
CVE-2026-27502MEDIUM6.1SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in log.php via the search query p...
CVE-2026-26745MEDIUM5.3OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration ...
CVE-2026-26100MEDIUM5.5Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network...
CVE-2026-26099MEDIUM5.5Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via ...
CVE-2026-26098MEDIUM5.5Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via ...
CVE-2026-26097MEDIUM5.5Uncontrolled Search Path Element in Owl opds 2.2.0.4 allows Leveraging/Manipulating Configuration File Search Paths via ...
CVE-2026-26096MEDIUM5.5Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network...
CVE-2026-26095MEDIUM5.5Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network...
CVE-2026-26049MEDIUM5.7The web management interface of the device renders the passwords in a plaintext input field. The current password is di...
CVE-2026-1842MEDIUM6.2HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and fa...
CVE-2026-24953MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple F...
CVE-2026-24946MEDIUM6.5Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-deliver...
CVE-2026-24944MEDIUM6.5Missing Authorization vulnerability in weDevs Subscribe2 subscribe2 allows Exploiting Incorrectly Configured Access Cont...
CVE-2026-22350MEDIUM6.5Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elem...
CVE-2026-22341MEDIUM6.7Authentication Bypass Using an Alternate Path or Channel vulnerability in Case-Themes Booked booked allows Authenticatio...
CVE-2026-2486MEDIUM6.4The Master Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ma_el_bh_tabl...
CVE-2026-26370MEDIUM6.1WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnera...
CVE-2026-2739MEDIUM5.5This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state...
CVE-2026-2384MEDIUM6.4The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortco...
CVE-2026-27017MEDIUM5.3uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for th...
CVE-2026-26994MEDIUM6.5uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for th...
CVE-2026-26993MEDIUM5.4Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Versions 1.7.0 and ...
CVE-2026-26992MEDIUM4.8LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port gro...
CVE-2026-26991MEDIUM4.8LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device g...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now