2026 CVE Vulnerabilities

43,769 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-50182MEDIUM6.1WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerabil...
CVE-2026-38974MEDIUM5.3Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.
CVE-2026-38754MEDIUM5.1A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv...
CVE-2026-26719MEDIUM6.1Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a cra...
CVE-2026-62361MEDIUM5.5listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscrib...
CVE-2026-56678MEDIUM6.49Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key...
CVE-2026-55608MEDIUM5.4n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-55410MEDIUM6.7NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-55399MEDIUM4.3CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with vali...
CVE-2026-52888MEDIUM6.8NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0....
CVE-2026-38753MEDIUM4.9A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv...
CVE-2026-33684MEDIUM5.3WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded ...
CVE-2026-33445MEDIUM5.9CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate ...
CVE-2026-56743MEDIUM5.4Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy s...
CVE-2026-49867MEDIUM6.3DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources le...
CVE-2026-45737MEDIUM6.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Ar...
CVE-2026-40953MEDIUM4.4CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers...
CVE-2026-33443MEDIUM5.9CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledg...
CVE-2026-62947MEDIUM4.9OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io aut...
CVE-2026-62355MEDIUM5.4TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Rea...
CVE-2026-62353MEDIUM5.4TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/p...
CVE-2026-62348MEDIUM5.4TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allo...
CVE-2026-54443MEDIUM5.9Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssF...
CVE-2026-49988MEDIUM6.8Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_...
CVE-2026-26032MEDIUM5.4The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now