2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-52773MEDIUM6.1YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view re...
CVE-2026-52772MEDIUM5.5YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to ...
CVE-2026-52763MEDIUM6.5YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) ac...
CVE-2026-86097MEDIUM6.5PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set...
CVE-2026-86096MEDIUM5.9PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race co...
CVE-2026-76925MEDIUM5.8A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatp...
CVE-2026-85787MEDIUM6.5An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before ve...
CVE-2026-85703MEDIUM6.5A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this iss...
CVE-2026-85701MEDIUM5.3A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue ...
CVE-2026-77847MEDIUM6.5Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability...
CVE-2026-53769MEDIUM6.5Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's di...
CVE-2026-85643MEDIUM4.7A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file adm...
CVE-2026-55513MEDIUM5.4nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the ne...
CVE-2026-55512MEDIUM5.3nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when O...
CVE-2026-53602MEDIUM6.9nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization ...
CVE-2026-85639MEDIUM5.6A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core...
CVE-2026-85637MEDIUM5.3A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the f...
CVE-2026-80115MEDIUM6.1PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 10...
CVE-2026-85769MEDIUM6.5A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for examp...
CVE-2026-85636MEDIUM5.3A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the ...
CVE-2026-84890MEDIUM5.9undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While t...
CVE-2026-73848MEDIUM6.9Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded w...
CVE-2026-61688MEDIUM6.5SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API reques...
CVE-2026-61614MEDIUM5.9SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tok...
CVE-2026-61608MEDIUM6.8SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry time...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now