2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-66063MEDIUM6.5goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown....
CVE-2026-59921MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-54659MEDIUM6.9Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18...
CVE-2026-59943MEDIUM5.3Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted con...
CVE-2026-56722MEDIUM5.3Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can byp...
CVE-2026-49447MEDIUM5.3Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as ...
CVE-2026-16581MEDIUM6.9In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulner...
CVE-2026-14515MEDIUM6.1IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scriptin...
CVE-2026-57511MEDIUM6.3SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject...
CVE-2026-3158MEDIUM4.3IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ...
CVE-2026-3157MEDIUM4.3IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ...
CVE-2026-1918MEDIUM4.9IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ...
CVE-2026-16192MEDIUM6.5IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability wh...
CVE-2026-16107MEDIUM5.9IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validat...
CVE-2026-11391MEDIUM6.3Tanium addressed a SQL injection vulnerability in Patch.
CVE-2026-7362MEDIUM6.5IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1...
CVE-2026-5114MEDIUM4.9The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and ...
CVE-2026-50735MEDIUM6.1pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol me...
CVE-2026-4932MEDIUM4.2IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physica...
CVE-2026-4912MEDIUM4.1The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio...
CVE-2026-48058MEDIUM4.6nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern...
CVE-2026-47768MEDIUM5.5nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-...
CVE-2026-47725MEDIUM6.9nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every ...
CVE-2026-15304MEDIUM6.5The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions ...
CVE-2026-48025MEDIUM6.9nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, intern...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now