2026 CVE Vulnerabilities

53,345 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-25828MEDIUM5.4grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because...
CVE-2026-26005MEDIUM5ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows ...
CVE-2026-26000MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0...
CVE-2026-0619MEDIUM6A reachable infinite loop via an integer wraparound is present in Silicon Labs' Matter SDK which allows an attacker to t...
CVE-2026-25933MEDIUM6.8Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in t...
CVE-2026-25768MEDIUM6.5LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadat...
CVE-2026-22821MEDIUM6.5mreporting is the more reporting GLPI plugin. Prior to 1.9.4, there is a possible SQL injection on date change. This vul...
CVE-2026-21438MEDIUM5.3webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memo...
CVE-2026-2003MEDIUM4.3Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. ...
CVE-2026-1671MEDIUM6.5The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2026-2276MEDIUM5.3Reflected Cross-Site Scripting (XSS) vulnerability in the Wix web application, where the endpoint ' https://manage.wix.c...
CVE-2026-1356MEDIUM4.8The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to Server-Side Reques...
CVE-2026-21722MEDIUM5.3Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the publi...
CVE-2026-1537MEDIUM5.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized a...
CVE-2026-20682MEDIUM5.3A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26....
CVE-2026-20680MEDIUM6.5The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7...
CVE-2026-20678MEDIUM5.5An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5...
CVE-2026-20676MEDIUM5.3This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3...
CVE-2026-20675MEDIUM5.5The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and i...
CVE-2026-20674MEDIUM4.6A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker w...
CVE-2026-20673MEDIUM5.3A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15....
CVE-2026-20669MEDIUM5.5A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m...
CVE-2026-20666MEDIUM5.5An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may...
CVE-2026-20662MEDIUM4.6An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS ...
CVE-2026-20661MEDIUM4.6An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now