2026 CVE Vulnerabilities

43,564 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-64192MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if ...
CVE-2026-64190MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: team: fix NULL pointer dereference in team_xmi...
CVE-2026-64187MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no ...
CVE-2026-58482MEDIUM5.9Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalI...
CVE-2026-58481MEDIUM6.5Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped fil...
CVE-2026-58414MEDIUM5.5Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recu...
CVE-2026-58413MEDIUM6.1Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, b...
CVE-2026-55645MEDIUM6.5xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client...
CVE-2026-55238MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Co...
CVE-2026-50743MEDIUM5.4A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or ...
CVE-2026-47276MEDIUM6.5In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attac...
CVE-2026-44978MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the ...
CVE-2026-42218MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login in...
CVE-2026-42210MEDIUM5.3Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that...
CVE-2026-35590MEDIUM6.8libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and in...
CVE-2026-35217MEDIUM6.5NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the fi...
CVE-2026-33328MEDIUM6.8libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.1...
CVE-2026-32823MEDIUM4.3dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32819MEDIUM4.3dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-6793MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering ...
CVE-2026-63428MEDIUM5.8HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id,...
CVE-2026-63102MEDIUM5.4rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitr...
CVE-2026-51026MEDIUM6.5Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a ...
CVE-2026-48824MEDIUM5.3Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2...
CVE-2026-46671MEDIUM4.4Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciou...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now