2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-89050MEDIUM4.3The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the confi...
CVE-2026-36989MEDIUM5.8A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.
CVE-2026-90583MEDIUM4.3A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected ...
CVE-2026-90582MEDIUM5.3A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file s...
CVE-2026-90581MEDIUM6.3A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpd...
CVE-2026-90580MEDIUM6.3A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the fi...
CVE-2026-29812MEDIUM4.3CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
CVE-2026-29810MEDIUM4.3CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.
CVE-2026-90578MEDIUM5.3A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/lis...
CVE-2026-90577MEDIUM5.3A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of...
CVE-2026-90574MEDIUM6.3A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of ...
CVE-2026-90572MEDIUM4.7A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient...
CVE-2026-90571MEDIUM4.3A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown functio...
CVE-2026-90565MEDIUM5.3A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e0...
CVE-2026-90527MEDIUM4.3A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admi...
CVE-2026-90525MEDIUM6.3A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the f...
CVE-2026-90782MEDIUM5.3S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items...
CVE-2026-90781MEDIUM4.4alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes o...
CVE-2026-90521MEDIUM6.3A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Th...
CVE-2026-90520MEDIUM6.3A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa6...
CVE-2026-90519MEDIUM6.3A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the f...
CVE-2026-90775MEDIUM6.5PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables befo...
CVE-2026-90518MEDIUM6.3A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of...
CVE-2026-90517MEDIUM5.3A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the ...
CVE-2026-90767MEDIUM6.5Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing cus...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now