2026 CVE Vulnerabilities

43,288 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10683MEDIUM4.6In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handl...
CVE-2026-66030MEDIUM5.4Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen...
CVE-2026-66029MEDIUM5.4Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent...
CVE-2026-64645MEDIUM6.1Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64644MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64643MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-54272MEDIUM6.9ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2...
CVE-2026-48052MEDIUM5.4Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i...
CVE-2026-17570MEDIUM4.3Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg...
CVE-2026-17569MEDIUM4.3Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per...
CVE-2026-66391MEDIUM6.5Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Ap...
CVE-2026-66390MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th...
CVE-2026-17531MEDIUM5A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality...
CVE-2026-47078MEDIUM4.8Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extrac...
CVE-2026-17574MEDIUM5.2HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an i...
CVE-2026-17573MEDIUM4A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized c...
CVE-2026-17572MEDIUM5.5Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows att...
CVE-2026-17530MEDIUM6.3A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function ...
CVE-2026-17529MEDIUM6.3A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/...
CVE-2026-66477MEDIUM5.3Unauthenticated Broken Access Control in Gillion <= 4.13 versions.
CVE-2026-66476MEDIUM4.9Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
CVE-2026-66475MEDIUM5.9Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versi...
CVE-2026-66474MEDIUM4.3Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.
CVE-2026-66448MEDIUM6.5Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
CVE-2026-66445MEDIUM6.5Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now