2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-87107MEDIUM5.4Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow...
CVE-2026-87106MEDIUM6.5Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenti...
CVE-2026-68527MEDIUM5.9Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (c...
CVE-2026-89045MEDIUM4zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.rea...
CVE-2026-89044MEDIUM6.5Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the f...
CVE-2026-88055MEDIUM5.5AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-88054MEDIUM5.5Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rej...
CVE-2026-88028MEDIUM6.5Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB inte...
CVE-2026-88026MEDIUM6.5Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# D...
CVE-2026-15417MEDIUM6.9In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to ...
CVE-2026-88050MEDIUM5.5Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharco...
CVE-2026-88049MEDIUM5.5Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks t...
CVE-2026-88046MEDIUM5.3rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-52097MEDIUM6.8An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (u...
CVE-2026-88940MEDIUM5.3knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attac...
CVE-2026-88938MEDIUM6.5knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agen...
CVE-2026-88015MEDIUM5.3rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-88014MEDIUM6.3rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72....
CVE-2026-88013MEDIUM5.3rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49....
CVE-2026-88012MEDIUM5.3Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints ...
CVE-2026-87913MEDIUM5.9A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote ...
CVE-2026-87912MEDIUM5.9A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1....
CVE-2026-81052MEDIUM6.8Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An una...
CVE-2026-81051MEDIUM6.6Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerabilit...
CVE-2026-81049MEDIUM6.7Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high priv...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now