2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-85381MEDIUM5.3A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a061...
CVE-2026-49509MEDIUM4.4Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 256...
CVE-2026-85456MEDIUM5.5MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowin...
CVE-2026-85454MEDIUM6.1MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a N...
CVE-2026-85453MEDIUM6.1MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to ...
CVE-2026-85241MEDIUM6.3A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of th...
CVE-2026-18330MEDIUM6.1A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who capt...
CVE-2026-9745MEDIUM6.5IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket owners...
CVE-2026-9744MEDIUM5.9IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validati...
CVE-2026-9736MEDIUM4.3IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages ...
CVE-2026-9036MEDIUM5.9IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validati...
CVE-2026-85063MEDIUM6.9node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-pars...
CVE-2026-85062MEDIUM6.9Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous...
CVE-2026-84185MEDIUM5.9A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE)...
CVE-2026-82521MEDIUM5.3parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject. ...
CVE-2026-71429MEDIUM6.2stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior...
CVE-2026-85044MEDIUM6.5Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker lever...
CVE-2026-19795MEDIUM6.2Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY p...
CVE-2026-85392MEDIUM4.3Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint...
CVE-2026-85389MEDIUM6.5Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing ...
CVE-2026-85205MEDIUM6.3A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addw...
CVE-2026-82299MEDIUM6.5Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Acc...
CVE-2026-82298MEDIUM4.3Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access C...
CVE-2026-78596MEDIUM4.3Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana...
CVE-2026-78595MEDIUM4.3Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now