2026 CVE Vulnerabilities

43,657 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-57896MEDIUM6.9An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti...
CVE-2026-36425MEDIUM6.5An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user...
CVE-2026-33731MEDIUM6.5WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/Aut...
CVE-2026-62299MEDIUM5.3CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an ...
CVE-2026-61718MEDIUM5.4bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb w...
CVE-2026-60140MEDIUM6.9An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti...
CVE-2026-54728MEDIUM6.1bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb ...
CVE-2026-15449MEDIUM5.8A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC...
CVE-2026-53536MEDIUM5.3Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endp...
CVE-2026-53535MEDIUM5.9Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf...
CVE-2026-47089MEDIUM4.3An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces...
CVE-2026-47085MEDIUM4An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk...
CVE-2026-47084MEDIUM6.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An aut...
CVE-2026-47083MEDIUM4.3An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u...
CVE-2026-47082MEDIUM5.4An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-ma...
CVE-2026-46514MEDIUM6.5Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword...
CVE-2026-46404MEDIUM6.8BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly res...
CVE-2026-46378MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1...
CVE-2026-46377MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1...
CVE-2026-46338MEDIUM4.3PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx....
CVE-2026-46341MEDIUM6.1The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation...
CVE-2026-44970MEDIUM4.3dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_call...
CVE-2026-44968MEDIUM6.3dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/...
CVE-2026-15737MEDIUM5.7AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on t...
CVE-2026-6511MEDIUM6.8During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now