2026 CVE Vulnerabilities

43,657 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-55548MEDIUM4.3Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/sr...
CVE-2026-55407MEDIUM6.3Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the dec...
CVE-2026-55406MEDIUM5.9Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a sound...
CVE-2026-50012MEDIUM5.5Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handli...
CVE-2026-47751MEDIUM5.3Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to...
CVE-2026-47729MEDIUM6.5Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in t...
CVE-2026-45795MEDIUM5.3The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server ac...
CVE-2026-45612MEDIUM5.5rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can...
CVE-2026-44595MEDIUM4.3Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGrou...
CVE-2026-10590MEDIUM6.7A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrar...
CVE-2026-10589MEDIUM6.8A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Manageme...
CVE-2026-10588MEDIUM6.7A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management...
CVE-2026-10587MEDIUM6.8A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management setting...
CVE-2026-63082MEDIUM5.4Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that a...
CVE-2026-63081MEDIUM5.4Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability ...
CVE-2026-57205MEDIUM4.3SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions...
CVE-2026-55440MEDIUM6.5Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND...
CVE-2026-54568MEDIUM4.3Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c...
CVE-2026-12379MEDIUM6.8An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard...
CVE-2026-59237MEDIUM6.9Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Pro...
CVE-2026-56456MEDIUM5.3HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently ...
CVE-2026-35143MEDIUM6.5HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" ...
CVE-2026-35141MEDIUM5.3HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce...
CVE-2026-9494MEDIUM5.5An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The cli...
CVE-2026-12391MEDIUM5An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) with...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now