2026 CVE Vulnerabilities

53,638 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-22253MEDIUM5.4Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the L...
CVE-2026-21860MEDIUM5.3Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows p...
CVE-2026-22587MEDIUM5.5Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a pa...
CVE-2026-22233MEDIUM5.4OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field...
CVE-2026-22232MEDIUM5.4OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project...
CVE-2026-22231MEDIUM5.4OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment within the Document Check Out functi...
CVE-2026-21896MEDIUM5.7Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in t...
CVE-2026-22522MEDIUM6.5Missing Authorization vulnerability in Munir Kamal Block Slider block-slider allows Exploiting Incorrectly Configured Ac...
CVE-2026-22519MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev MediaPres...
CVE-2026-22518MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons ...
CVE-2026-22517MEDIUM5.4Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiti...
CVE-2026-22492MEDIUM4.3Missing Authorization vulnerability in Nawawi Jamili Docket Cache docket-cache allows Exploiting Incorrectly Configured ...
CVE-2026-22490MEDIUM5.4Missing Authorization vulnerability in niklaslindemann Bulk Landing Page Creator for WordPress LPagery lpagery allows Ex...
CVE-2026-22489MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow image-slider-slidesho...
CVE-2026-22488MEDIUM5.3Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beav...
CVE-2026-22487MEDIUM4.3Missing Authorization vulnerability in baqend Speed Kit baqend allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-22486MEDIUM5.3Missing Authorization vulnerability in Re Gallery allows Exploiting Incorrectly Configured Access Control Security Level...
CVE-2026-0671MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-22246MEDIUM4.3Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed ...
CVE-2026-22041MEDIUM5.3Logging Redactor is a Python library designed to redact sensitive data in logs based on regex patterns and / or dictiona...
CVE-2026-22032MEDIUM6.1Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redir...
CVE-2026-22028MEDIUM6.1Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from bein...
CVE-2026-21895MEDIUM5.3The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from ...
CVE-2026-21885MEDIUM6.5Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encoded...
CVE-2026-21876MEDIUM5.3The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewal...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now