2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-71802MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement preview component of REBUILD 4.4.3. Althoug...
CVE-2026-53956MEDIUM5.4Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to versio...
CVE-2026-73789MEDIUM5.3A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthent...
CVE-2026-73788MEDIUM6.5A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privile...
CVE-2026-71616MEDIUM6.2An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the functi...
CVE-2026-61911MEDIUM4.3An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user co...
CVE-2026-61910MEDIUM5An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailbo...
CVE-2026-61909MEDIUM4.3An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated D...
CVE-2026-61908MEDIUM6.5An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. A...
CVE-2026-38998MEDIUM6.5A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Med...
CVE-2026-61907MEDIUM4.3An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated ...
CVE-2026-39020MEDIUM5.5An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file
CVE-2026-87928MEDIUM5.4MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler th...
CVE-2026-87875MEDIUM4.3The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the s...
CVE-2026-87872MEDIUM6.8A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The share...
CVE-2026-85788MEDIUM5.5Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allo...
CVE-2026-70425MEDIUM6.7Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 throug...
CVE-2026-40635MEDIUM5.4Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privile...
CVE-2026-81330MEDIUM6.5The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The applicatio...
CVE-2026-79947MEDIUM5.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79946MEDIUM5.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79945MEDIUM5.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79741MEDIUM5.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79735MEDIUM4.4Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-83530MEDIUM4.3A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now