2026 CVE Vulnerabilities

43,583 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-54464MEDIUM6.3### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can ...
CVE-2026-54171MEDIUM6.5Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip add...
CVE-2026-50162MEDIUM6.9oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a le...
CVE-2026-4938MEDIUM6.5IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident...
CVE-2026-48819MEDIUM4.8Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/pa...
CVE-2026-48504MEDIUM5.3OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_cont...
CVE-2026-46420MEDIUM5.6setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.2...
CVE-2026-15995MEDIUM4.2IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain inc...
CVE-2026-15415MEDIUM6.8AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure ...
CVE-2026-15093MEDIUM4.3IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due...
CVE-2026-15069MEDIUM5.4IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to imp...
CVE-2026-12283MEDIUM6.8Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard...
CVE-2026-48487MEDIUM5.3Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string a...
CVE-2026-48045MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_que...
CVE-2026-47184MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inser...
CVE-2026-47183MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exceptio...
CVE-2026-47180MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_label...
CVE-2026-45703MEDIUM6.4Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport expor...
CVE-2026-48016MEDIUM4.3Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment...
CVE-2026-48015MEDIUM4.9Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelis...
CVE-2026-48014MEDIUM6.5Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action...
CVE-2026-48010MEDIUM6.5Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framewo...
CVE-2026-48009MEDIUM6.8Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:re...
CVE-2026-48008MEDIUM6.5Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL...
CVE-2026-63309MEDIUM4.3SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now