2026 CVE Vulnerabilities

53,578 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-21934MEDIUM5.4Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Push Notifications). Su...
CVE-2026-21933MEDIUM6.1Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2026-21931MEDIUM5.4Vulnerability in the Oracle APEX Sample Applications product of Oracle APEX (component: Brookstrut Sample App). Support...
CVE-2026-21929MEDIUM5.3Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affe...
CVE-2026-21928MEDIUM5.3Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affec...
CVE-2026-21927MEDIUM5.8Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affec...
CVE-2026-21925MEDIUM4.8Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2026-21924MEDIUM5.4Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General...
CVE-2026-21923MEDIUM6.5Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Pl...
CVE-2026-21922MEDIUM4.2Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th...
CVE-2026-0865MEDIUM5.9User-controlled header names and values containing newlines can allow injecting HTTP headers.
CVE-2026-0672MEDIUM6When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messa...
CVE-2026-21664MEDIUM6.1HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php de...
CVE-2026-21663MEDIUM6.1HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of...
CVE-2026-21642MEDIUM6.1HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `ch...
CVE-2026-21641MEDIUM6.5HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-dele...
CVE-2026-0622MEDIUM6.5Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset
CVE-2026-1245MEDIUM6.5A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code exec...
CVE-2026-0690MEDIUM6.4The FlatPM – Ad Manager, AdSense and Custom Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2026-0608MEDIUM6.4The Head Meta Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head-meta-data' post meta ...
CVE-2026-0554MEDIUM4.3The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2026-0548MEDIUM5.4The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized attachment delet...
CVE-2026-1183MEDIUM5.1HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an ...
CVE-2026-1180MEDIUM5.8A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using p...
CVE-2026-0895MEDIUM5.2The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now