2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-86764MEDIUM6.5Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GE...
CVE-2026-86761MEDIUM4.3snipe-it versions before 8.7.0 contain an authorization bypass vulnerability in location print endpoints that fails to e...
CVE-2026-86760MEDIUM5.4Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/U...
CVE-2026-86758MEDIUM6.5Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, a...
CVE-2026-86757MEDIUM6.5Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox...
CVE-2026-86756MEDIUM6.1Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlContro...
CVE-2026-86755MEDIUM5.4Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST,...
CVE-2026-86753MEDIUM4.3snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset...
CVE-2026-86752MEDIUM5.4snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on que...
CVE-2026-86749MEDIUM6.3Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequ...
CVE-2026-86748MEDIUM6.1Snipe-IT versions before 8.7.0 wipe the database before validating the uploaded backup archive in the restore endpoint. ...
CVE-2026-86747MEDIUM5.4Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endp...
CVE-2026-86746MEDIUM6.4Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization o...
CVE-2026-86745MEDIUM6.5Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never include...
CVE-2026-86743MEDIUM5Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated...
CVE-2026-86742MEDIUM6.5Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. Rep...
CVE-2026-86739MEDIUM6.5Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the genera...
CVE-2026-86204MEDIUM6.5PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authe...
CVE-2026-86202MEDIUM4.3PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that all...
CVE-2026-86200MEDIUM5.3PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows re...
CVE-2026-86198MEDIUM4.2PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with ST...
CVE-2026-79971MEDIUM5.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79964MEDIUM5.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79952MEDIUM5.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...
CVE-2026-79731MEDIUM4.4Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now