2026 CVE Vulnerabilities

43,494 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-56144MEDIUM6.5Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl...
CVE-2026-49092MEDIUM4.3Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v...
CVE-2026-47671MEDIUM5.4Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost c...
CVE-2026-46403MEDIUM6.3Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithT...
CVE-2026-42397MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A...
CVE-2026-16441MEDIUM6.9In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been...
CVE-2026-12548MEDIUM4.2A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch betw...
CVE-2026-56577MEDIUM6.5HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force o...
CVE-2026-47425MEDIUM6.9Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `Entry...
CVE-2026-47411MEDIUM6.5PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut...
CVE-2026-21577MEDIUM6.5This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9...
CVE-2026-47408MEDIUM6.5PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins...
CVE-2026-24232MEDIUM4.3NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data...
CVE-2026-16454MEDIUM4.3In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie...
CVE-2026-16451MEDIUM6.3A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts...
CVE-2026-15342MEDIUM6.5Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one wo...
CVE-2026-64823MEDIUM4.7Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_...
CVE-2026-56586MEDIUM4.2HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man...
CVE-2026-56585MEDIUM4.3HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the appli...
CVE-2026-47395MEDIUM5.5PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso...
CVE-2026-47390MEDIUM5.5PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso...
CVE-2026-28315MEDIUM6.2SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hij...
CVE-2026-16450MEDIUM4.3A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the ...
CVE-2026-16449MEDIUM6.3A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted elem...
CVE-2026-65051MEDIUM6.9Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability tha...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now