2026 CVE Vulnerabilities

64,751 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7301CRITICAL9.8SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that cal...
CVE-2026-0983HIGH7.1Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 all...
CVE-2026-8802MEDIUM5.3A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function get...
CVE-2026-4320CRITICAL9.3Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to pr...
CVE-2026-41119MEDIUM6.8Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A rem...
CVE-2026-7498HIGH8.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Informatio...
CVE-2026-6902HIGH7.7A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has ...
CVE-2026-6347HIGH7.6Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie...
CVE-2026-6346HIGH8.7Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie...
CVE-2026-6345MEDIUM6.5Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user pass...
CVE-2026-6343MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions whi...
CVE-2026-6339MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read ...
CVE-2026-6333MEDIUM5Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response UR...
CVE-2026-5163MEDIUM6.5Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites whic...
CVE-2026-4643LOW3.5Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying ...
CVE-2026-4286MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating p...
CVE-2026-3471MEDIUM6.5Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in t...
CVE-2026-3117MEDIUM6.5Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing comma...
CVE-2026-28732MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word u...
CVE-2026-8788HIGH7.3Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were n...
CVE-2026-6342MEDIUM4.3Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allow...
CVE-2026-6341MEDIUM4.3Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which groups the user can c...
CVE-2026-6340MEDIUM6.5Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure befo...
CVE-2026-6334LOW3.8Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth autho...
CVE-2026-4273MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the orig...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now