2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-39020MEDIUM5.5An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file
CVE-2026-87928MEDIUM5.4MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler th...
CVE-2026-87875MEDIUM4.3The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the s...
CVE-2026-87872MEDIUM6.8A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The share...
CVE-2026-85788MEDIUM5.5Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allo...
CVE-2026-70425MEDIUM6.7Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 throug...
CVE-2026-40635MEDIUM5.4Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privile...
CVE-2026-81330MEDIUM6.5The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The applicatio...
CVE-2026-79947MEDIUM5.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79946MEDIUM5.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79945MEDIUM5.5Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79741MEDIUM5.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79735MEDIUM4.4Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-83530MEDIUM4.3A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the ...
CVE-2026-82530MEDIUM5.3IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allo...
CVE-2026-86774MEDIUM6.3Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() metho...
CVE-2026-86773MEDIUM5.4Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updat...
CVE-2026-86772MEDIUM5.4Snipe-IT versions before 8.7.0 contain a stored cross-site scripting vulnerability in DepartmentPresenter::formattedName...
CVE-2026-86769MEDIUM4.3Snipe-IT versions before 8.7.0 contain an improper ownership management vulnerability in the consumables checkout API en...
CVE-2026-86768MEDIUM5.4Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with ...
CVE-2026-86767MEDIUM5Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full M...
CVE-2026-86766MEDIUM6.5Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (P...
CVE-2026-86765MEDIUM6.5Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset ...
CVE-2026-86764MEDIUM6.5Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GE...
CVE-2026-86761MEDIUM4.3snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to e...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now