2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-82054MEDIUM6.5A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a ...
CVE-2026-82052MEDIUM6.5The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a Mon...
CVE-2026-81531MEDIUM6.9An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controlle...
CVE-2026-78230MEDIUM6AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, s...
CVE-2026-78216MEDIUM6AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, ...
CVE-2026-52307MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5....
CVE-2026-22575MEDIUM4.9An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10...
CVE-2026-86853MEDIUM4.3A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launch...
CVE-2026-86737MEDIUM4.3snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. A...
CVE-2026-86736MEDIUM4.3snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authentic...
CVE-2026-86735MEDIUM5snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule th...
CVE-2026-86734MEDIUM6.5Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, ...
CVE-2026-86731MEDIUM6.5Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (t...
CVE-2026-86726MEDIUM6.5AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticat...
CVE-2026-86724MEDIUM6.5AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in pl...
CVE-2026-86719MEDIUM5.4WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulne...
CVE-2026-79573MEDIUM6.5L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList c...
CVE-2026-56101MEDIUM5.3OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() funct...
CVE-2026-84282MEDIUM6.5A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. Th...
CVE-2026-12387MEDIUM5.1Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2026-12285MEDIUM4Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2026-11891MEDIUM5.1Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Dri...
CVE-2026-0001MEDIUM4.4Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge...
CVE-2026-79379MEDIUM6.5A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x an...
CVE-2026-78838MEDIUM6.5A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now