2026 CVE Vulnerabilities

53,349 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-21317MEDIUM5.5Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposur...
CVE-2026-21316MEDIUM5.5Audition versions 25.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerability that c...
CVE-2026-21315MEDIUM5.5Audition versions 25.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposur...
CVE-2026-21314MEDIUM5.5Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposur...
CVE-2026-21313MEDIUM5.5Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposur...
CVE-2026-21261MEDIUM5.5Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-21258MEDIUM5.5Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-21222MEDIUM5.5Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information...
CVE-2026-1997MEDIUM5.3Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, poten...
CVE-2026-1996MEDIUM5.3Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled,...
CVE-2026-0653MEDIUM6.5On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending...
CVE-2026-25530MEDIUM4.3Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks...
CVE-2026-1602MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2026-1922MEDIUM6.4The The Events Calendar Shortcode & Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2026-1722MEDIUM5.3The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Obj...
CVE-2026-2099MEDIUM5.4AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers...
CVE-2026-2098MEDIUM6.1AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote atta...
CVE-2026-0996MEDIUM6.4The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI Form Builder module in all...
CVE-2026-2259MEDIUM5.5A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser...
CVE-2026-24328MEDIUM6.1SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when cli...
CVE-2026-24327MEDIUM4.3Due to missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in Business Server Pages),...
CVE-2026-24326MEDIUM4.3Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker w...
CVE-2026-24325MEDIUM4.8SAP BusinessObjects Enterprise does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripti...
CVE-2026-24324MEDIUM6.5SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to...
CVE-2026-24323MEDIUM6.1The BSP applications allow an unauthenticated user to inject malicious script content via user-controlled URL parameters...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now