2026 CVE Vulnerabilities

44,807 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-55432MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55431MEDIUM6.1Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55430MEDIUM6.8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55079MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and pr...
CVE-2026-55078MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and pr...
CVE-2026-50811MEDIUM6.5An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736...
CVE-2026-50810MEDIUM5.5A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35...
CVE-2026-36163MEDIUM5.4An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execut...
CVE-2026-36162MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 all...
CVE-2026-58266MEDIUM6.5Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with t...
CVE-2026-55490MEDIUM6.5OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a()...
CVE-2026-54698MEDIUM6Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a ...
CVE-2026-54601MEDIUM6.3FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticat...
CVE-2026-50179MEDIUM4.2Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/s...
CVE-2026-45796MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13...
CVE-2026-58470MEDIUM6.9GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range(...
CVE-2026-55647MEDIUM5.1DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stor...
CVE-2026-55434MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and pr...
CVE-2026-55417MEDIUM6.9Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user ena...
CVE-2026-53935MEDIUM6.9Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 t...
CVE-2026-46700MEDIUM4.3Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-serve...
CVE-2026-46672MEDIUM4.6Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in pac...
CVE-2026-58468MEDIUM5.5NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows au...
CVE-2026-44877MEDIUM6.5An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960...
CVE-2026-55435MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now