2026 CVE Vulnerabilities

53,599 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-23493MEDIUM4.9Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file st...
CVE-2026-22867MEDIUM5.4LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Sc...
CVE-2026-20076MEDIUM4.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2026-20075MEDIUM4.8A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri...
CVE-2026-20047MEDIUM4.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Iden...
CVE-2026-0990MEDIUM5.9A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogX...
CVE-2026-22645MEDIUM5.3The application discloses all used components, versions and license information to unauthenticated actors, giving attack...
CVE-2026-22919MEDIUM4.8An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site...
CVE-2026-22916MEDIUM5.4An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without...
CVE-2026-22915MEDIUM6.5An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing ...
CVE-2026-22914MEDIUM6.5An attacker with limited permissions may still be able to write files to specific locations on the device, potentially l...
CVE-2026-22913MEDIUM6.1Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead ...
CVE-2026-22912MEDIUM6.1Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authenticatio...
CVE-2026-0600MEDIUM6.2Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenti...
CVE-2026-0601MEDIUM5.1A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to exe...
CVE-2026-0962MEDIUM6.5SOME/IP-SD protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
CVE-2026-0961MEDIUM6.5BLF file parser crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
CVE-2026-0960MEDIUM5.5HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
CVE-2026-0959MEDIUM6.5IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.2 and 4.4.0 to 4.4.12 allows denial of service
CVE-2026-23497MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and ear...
CVE-2026-23492MEDIUM4.9Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injectio...
CVE-2026-23477MEDIUM6.5Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0,...
CVE-2026-22851MEDIUM5.9FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dy...
CVE-2026-22787MEDIUM6.1html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js cont...
CVE-2026-22779MEDIUM5.3BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now