2026 CVE Vulnerabilities

43,858 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33213MEDIUM6.1Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's a...
CVE-2026-59838MEDIUM4.8A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4....
CVE-2026-58559MEDIUM6.5DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availabilit...
CVE-2026-58557MEDIUM4.8Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availab...
CVE-2026-58556MEDIUM5.1Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affe...
CVE-2026-58555MEDIUM6.6Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect ava...
CVE-2026-58554MEDIUM6.6Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-58553MEDIUM4Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af...
CVE-2026-58552MEDIUM5.1Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af...
CVE-2026-58551MEDIUM5.1Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af...
CVE-2026-58550MEDIUM4Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af...
CVE-2026-58549MEDIUM4Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af...
CVE-2026-46459MEDIUM5.3ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows a...
CVE-2026-15779MEDIUM6.1A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directo...
CVE-2026-61871MEDIUM6.3ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocatio...
CVE-2026-61868MEDIUM6.3ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when openin...
CVE-2026-61860MEDIUM6.3ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initializati...
CVE-2026-61859MEDIUM4.8ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operatio...
CVE-2026-61453MEDIUM6.1Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detec...
CVE-2026-61452MEDIUM6.9The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where...
CVE-2026-60087MEDIUM6.9PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals ...
CVE-2026-59259MEDIUM6.5n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling...
CVE-2026-59254MEDIUM6.3n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in wo...
CVE-2026-59236MEDIUM6.9Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, Pro...
CVE-2026-56764MEDIUM6.3Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-consta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now