2026 CVE Vulnerabilities

57,105 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14624MEDIUM4.3A vulnerability was identified in omec-project amf up to 2.0.2/2.1.1. Impacted is an unknown function of the file /go/sr...
CVE-2026-14623MEDIUM4.3A vulnerability was determined in omec-project amf up to 2.1.1. This issue affects the function RRCInactiveTransitionRep...
CVE-2026-14622HIGH7.3A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. Th...
CVE-2026-14621LOW3.1A vulnerability has been found in FederatedAI FATE up to 2.2.0. This affects the function QueuePushReqStreamObserver.ini...
CVE-2026-14619MEDIUM6.3A flaw has been found in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionali...
CVE-2026-12194LOW2.3PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to e...
CVE-2026-14618MEDIUM4.3A vulnerability was detected in Open5GS up to 2.7.7. Affected by this vulnerability is the function amf_nnrf_handle_nf_d...
CVE-2026-12252HIGH7.8In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, Stanford...
CVE-2026-54424HIGH8.4An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Pri...
CVE-2026-58523MEDIUM6.5Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over ...
CVE-2026-14617LOW3.1A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function Gatewa...
CVE-2026-58597MEDIUM4.3Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to pe...
CVE-2026-58524MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ...
CVE-2026-58522MEDIUM6.8Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2026-58426CRITICAL9.6Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state w...
CVE-2026-58424HIGH8.9Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-58423HIGH7.7LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
CVE-2026-58422CRITICAL9.8Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58421HIGH7.5Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-58419HIGH7.5Notification API leaks private issue metadata after access revocation
CVE-2026-58418MEDIUM6.5SSRF via HTTP Redirect in Repository Migration
CVE-2026-58300MEDIUM6.2Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2026-58299HIGH7.5Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execu...
CVE-2026-58298MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ...
CVE-2026-58297HIGH7.1Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now