2026 CVE Vulnerabilities

53,386 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-23060MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject too-short AAD (assoclen...
CVE-2026-20123MEDIUM6.1A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri...
CVE-2026-20111MEDIUM4.8A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote...
CVE-2026-20056MEDIUM4A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco S...
CVE-2026-22549MEDIUM6.9A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secr...
CVE-2026-20732MEDIUM4.3A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error mes...
CVE-2026-0873MEDIUM4.8On a Cryptobox platform where administrator segregation based on entities is used, some vulnerabilities in Ercom Cryptob...
CVE-2026-1622MEDIUM4.8Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential informatio...
CVE-2026-1370MEDIUM4.9The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedI...
CVE-2026-0816MEDIUM4.9The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' para...
CVE-2026-0743MEDIUM4.4The WP Content Permission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ohmem-message' para...
CVE-2026-0742MEDIUM6.4The Smart Appointment & Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saab_save_form...
CVE-2026-0681MEDIUM4.4The Extended Random Number Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin se...
CVE-2026-0679MEDIUM5.3The Fortis for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to an inverted nonce check in ...
CVE-2026-0572MEDIUM6.5The WebPurify Profanity Filter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2026-24447MEDIUM6.5If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such m...
CVE-2026-23704MEDIUM6.5A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitr...
CVE-2026-22875MEDIUM5.4Movable Type contains a stored cross-site scripting vulnerability in Export Sites. If crafted input is stored by an atta...
CVE-2026-21393MEDIUM5.4Movable Type contains a stored cross-site scripting vulnerability in Edit Comment. If crafted input is stored by an atta...
CVE-2026-20986MEDIUM5.5Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Sam...
CVE-2026-20985MEDIUM4.3Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL...
CVE-2026-20984MEDIUM5.1Improper handling of insufficient permission in Galaxy Wearable installed on non-Samsung Device prior to version 2.2.68 ...
CVE-2026-20982MEDIUM6Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with s...
CVE-2026-20981MEDIUM6.6Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execut...
CVE-2026-20980MEDIUM6.8Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now