2026 CVE Vulnerabilities

53,386 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-20978MEDIUM6.1Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persiste...
CVE-2026-20977MEDIUM5.5Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its fun...
CVE-2026-1835MEDIUM4.3A vulnerability was identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. This affects an unknown...
CVE-2026-24514MEDIUM6.5A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denia...
CVE-2026-1755MEDIUM6.4The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_wp_attachment_im...
CVE-2026-25509MEDIUM5.3CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-25151MEDIUM5.9Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inc...
CVE-2026-25149MEDIUM6.1Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City...
CVE-2026-25148MEDIUM6.1Qwik is a performance focused javascript framework. Prior to version 1.19.0, a Cross-Site Scripting vulnerability in Qwi...
CVE-2026-24053MEDIUM6.5Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clo...
CVE-2026-1801MEDIUM6.5A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RF...
CVE-2026-25616MEDIUM6.1Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.
CVE-2026-24441MEDIUM5.9Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP respon...
CVE-2026-24434MEDIUM6.5Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative fun...
CVE-2026-25522MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s...
CVE-2026-25490MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s...
CVE-2026-25489MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s...
CVE-2026-25488MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s...
CVE-2026-25487MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s...
CVE-2026-25486MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. From version 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft ...
CVE-2026-25485MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s...
CVE-2026-25484MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, the...
CVE-2026-25483MEDIUM5.4Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s...
CVE-2026-25482MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s...
CVE-2026-24427MEDIUM5.5Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose sensitive information in web management responses. ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now