2026 CVE Vulnerabilities

53,211 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-0549MEDIUM6.4The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortc...
CVE-2026-2683MEDIUM4.3A vulnerability was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). The affected element is an ...
CVE-2026-2676MEDIUM6.3A weakness has been identified in GoogTech sms-ssm up to e8534c766fd13f5f94c01dab475d75f286918a8d. Affected by this issu...
CVE-2026-26281MEDIUM4.4InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A stored cross-site ...
CVE-2026-26270MEDIUM5.4InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ...
CVE-2026-25596MEDIUM4.8InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ...
CVE-2026-25595MEDIUM4.8InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ...
CVE-2026-25594MEDIUM4.8InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site ...
CVE-2026-2672MEDIUM5.3A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this ...
CVE-2026-2669MEDIUM6.5A vulnerability was determined in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This impac...
CVE-2026-27178MEDIUM6.1MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability through method paramete...
CVE-2026-27177MEDIUM6.1MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability via the /objects/?op=se...
CVE-2026-27176MEDIUM6.1MajorDoMo (aka Major Domestic Module) contains a reflected cross-site scripting (XSS) vulnerability in command.php. The ...
CVE-2026-2667MEDIUM5.5A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impact...
CVE-2026-1999MEDIUM6.5An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge th...
CVE-2026-1355MEDIUM6.5A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unau...
CVE-2026-1200MEDIUM6.3A flaw was found in the rgaufman/live555 fork of live555. A remote attacker could exploit a segmentation fault, in the `...
CVE-2026-0665MEDIUM6.5An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-b...
CVE-2026-2665MEDIUM6.3A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the fu...
CVE-2026-2663MEDIUM6.3A security vulnerability has been detected in Alixhan xh-admin-backend up to 1.7.0. This issue affects some unknown proc...
CVE-2026-25500MEDIUM5.4Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory` generates an...
CVE-2026-2658MEDIUM4.3A vulnerability was found in newbee-ltd newbee-mall up to a069069b07027613bf0e7f571736be86f431faee. Affected is an unkno...
CVE-2026-20144MEDIUM4.9In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 1...
CVE-2026-20142MEDIUM4.9In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SH...
CVE-2026-20141MEDIUM6.5In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now