2026 CVE Vulnerabilities

53,578 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1223MEDIUM6.9PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability,...
CVE-2026-1218MEDIUM6.3A vulnerability was detected in Bjskzy Zhiyou ERP up to 11.0. Impacted is the function initRCForm of the file RichClient...
CVE-2026-1045MEDIUM4.4The Viet contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-1042MEDIUM4.4The WP Hello Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'digit_one' and 'digit_two' p...
CVE-2026-0904MEDIUM5.4Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perfor...
CVE-2026-0903MEDIUM5.4Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker t...
CVE-2026-0901MEDIUM5.4Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to pe...
CVE-2026-1051MEDIUM4.3The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in ...
CVE-2026-23950MEDIUM5.9node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an ...
CVE-2026-23874MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-1...
CVE-2026-1196MEDIUM5.3A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/get...
CVE-2026-22218MEDIUM6.5Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An au...
CVE-2026-23886MEDIUM5.3Swift W3C TraceContext is a Swift implementation of the W3C Trace Context standard, and Swift OTel is an OpenTelemetry P...
CVE-2026-23877MEDIUM4.3Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's `list_folders()` ...
CVE-2026-23875MEDIUM5.4CrawlChat is an open-source, AI-powered platform that transforms technical documentation into intelligent chatbots. Prio...
CVE-2026-23849MEDIUM5.3File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview,...
CVE-2026-23848MEDIUM5.3MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypas...
CVE-2026-23844MEDIUM4.3Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulner...
CVE-2026-23851MEDIUM6.5SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file...
CVE-2026-23847MEDIUM6.1SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripti...
CVE-2026-21696MEDIUM6.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version...
CVE-2026-23878MEDIUM6.5HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ce...
CVE-2026-23841MEDIUM6.1Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a...
CVE-2026-23840MEDIUM6.1Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a...
CVE-2026-23839MEDIUM6.1Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now