2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-91132MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildca...
CVE-2026-88384MEDIUM5.5OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file conta...
CVE-2026-88367MEDIUM6.5NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasteriz...
CVE-2026-84302MEDIUM4.2Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI revie...
CVE-2026-79763MEDIUM5.3Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0...
CVE-2026-79762MEDIUM5.5Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0...
CVE-2026-47132MEDIUM5.4phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injecti...
CVE-2026-26054MEDIUM6.8SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp vali...
CVE-2026-97226MEDIUM6.3A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the ...
CVE-2026-97225MEDIUM6.3A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/contro...
CVE-2026-96873MEDIUM5.5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cirrus...
CVE-2026-96746MEDIUM6.5An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who...
CVE-2026-96745MEDIUM5.6Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embe...
CVE-2026-93541MEDIUM6.5An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a
CVE-2026-92680MEDIUM5.5Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the W...
CVE-2026-88370MEDIUM5.3libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and stri...
CVE-2026-79761MEDIUM6.6Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0...
CVE-2026-79760MEDIUM6.4Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0...
CVE-2026-79759MEDIUM4.3Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0...
CVE-2026-79758MEDIUM5.4Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0...
CVE-2026-76907MEDIUM6.5LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/docum...
CVE-2026-67233MEDIUM6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel ma...
CVE-2026-97224MEDIUM4.3A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file package...
CVE-2026-77825MEDIUM4.9IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint...
CVE-2026-77707MEDIUM5.9Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM)...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now