2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-57166MEDIUM5.3PJSIP is a free and open source multimedia communication library written in C. Prior to commit 4472a31, a stack buffer o...
CVE-2026-57165MEDIUM5.3PJSIP is a free and open source multimedia communication library written in C. Prior to commit 628b716, a stack buffer o...
CVE-2026-57164MEDIUM5.9PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer ov...
CVE-2026-57160MEDIUM5.3PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflo...
CVE-2026-53760MEDIUM5.2Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handl...
CVE-2026-53757MEDIUM6.9Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP e...
CVE-2026-53756MEDIUM4.9Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection i...
CVE-2026-18149MEDIUM5.9undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful re...
CVE-2026-85024MEDIUM5.9undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zl...
CVE-2026-85008MEDIUM5.3undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by s...
CVE-2026-84947MEDIUM5.3undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares...
CVE-2026-78849MEDIUM5.4Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2....
CVE-2026-38961MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense...
CVE-2026-18078MEDIUM6.5IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer ...
CVE-2026-18076MEDIUM6.5IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory le...
CVE-2026-18073MEDIUM4.4IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to im...
CVE-2026-17631MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to...
CVE-2026-17622MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to...
CVE-2026-17621MEDIUM5.4IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker c...
CVE-2026-17469MEDIUM5.5IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-on...
CVE-2026-17444MEDIUM6.5IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1...
CVE-2026-17443MEDIUM6.5IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1...
CVE-2026-17442MEDIUM5.5IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1...
CVE-2026-17440MEDIUM5.5IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1...
CVE-2026-17274MEDIUM5.4IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predicta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now