2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-79725MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to imprope...
CVE-2026-79723MEDIUM5IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to...
CVE-2026-79590MEDIUM6.5A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a ...
CVE-2026-71642MEDIUM4An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an att...
CVE-2026-54054MEDIUM6.5Transmute is a free, open-source, self-hosted file conversion and compression tool. Prior to version 1.3.0, Transmute's ...
CVE-2026-49838MEDIUM5.9GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4....
CVE-2026-49837MEDIUM5.9GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4...
CVE-2026-49836MEDIUM4.6psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` ...
CVE-2026-45767MEDIUM4.4Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-36392MEDIUM5.4FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject...
CVE-2026-9667MEDIUM5.3IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a rem...
CVE-2026-9225MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging...
CVE-2026-89089MEDIUM6.5A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridi...
CVE-2026-76653MEDIUM5.3A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 &...
CVE-2026-76652MEDIUM4.8An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2,...
CVE-2026-45752MEDIUM5.9Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. St...
CVE-2026-45751MEDIUM5.9Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-3096MEDIUM4.7The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the origina...
CVE-2026-19596MEDIUM5.9An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Hori...
CVE-2026-88061MEDIUM5.8career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops loca...
CVE-2026-84432MEDIUM5.3Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/...
CVE-2026-9338MEDIUM5.3IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafte...
CVE-2026-88059MEDIUM4Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-88057MEDIUM5.3Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-88035MEDIUM5.5A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now