2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-52822MEDIUM5.3Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/times...
CVE-2026-52821MEDIUM5.3Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{p...
CVE-2026-52820MEDIUM5.3Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets ...
CVE-2026-52819MEDIUM6.3Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user a...
CVE-2026-1759MEDIUM6.5Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escala...
CVE-2026-91859MEDIUM5.3Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because Ca...
CVE-2026-91857MEDIUM5.3Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affec...
CVE-2026-62280MEDIUM6.1Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoin...
CVE-2026-59341MEDIUM4.2A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modif...
CVE-2026-44202MEDIUM5.3Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListene...
CVE-2026-91851MEDIUM5.3Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. Da...
CVE-2026-91826MEDIUM4.4Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to...
CVE-2026-91819MEDIUM6.9Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-sec...
CVE-2026-91091MEDIUM4.3A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of...
CVE-2026-91089MEDIUM6.3A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegrap...
CVE-2026-91088MEDIUM4.8A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file...
CVE-2026-91086MEDIUM6.3A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_proc...
CVE-2026-91005MEDIUM6.3A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded...
CVE-2026-89141MEDIUM6.5The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Obje...
CVE-2026-18063MEDIUM6.4The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter i...
CVE-2026-15402MEDIUM6.4The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to S...
CVE-2026-91002MEDIUM5.3A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of t...
CVE-2026-81320MEDIUM5.5A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log lev...
CVE-2026-81303MEDIUM6.3A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the...
CVE-2026-18232MEDIUM5.3The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now