2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6426MEDIUM4.4A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size...
CVE-2026-73035MEDIUM5.3npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t...
CVE-2026-72912MEDIUM4.3CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec...
CVE-2026-72908MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template...
CVE-2026-72907MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function ...
CVE-2026-72906MEDIUM4.3ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email ...
CVE-2026-72743MEDIUM5.4SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb...
CVE-2026-18942MEDIUM5.5A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th...
CVE-2026-16456MEDIUM6.5A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex...
CVE-2026-72881MEDIUM6.4Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command bui...
CVE-2026-72873MEDIUM6.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/...
CVE-2026-69116MEDIUM6.1FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives....
CVE-2026-44401MEDIUM4.8Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that ...
CVE-2026-71968MEDIUM6.7OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo...
CVE-2026-71967MEDIUM5.7OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pse...
CVE-2026-6791MEDIUM6.6When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the ...
CVE-2026-68872MEDIUM6.5The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team...
CVE-2026-68871MEDIUM6.5The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id ...
CVE-2026-68870MEDIUM5.3The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va...
CVE-2026-12339MEDIUM6.9A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive contai...
CVE-2026-72739MEDIUM6.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs...
CVE-2026-72732MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp...
CVE-2026-72728MEDIUM6.3Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed ...
CVE-2026-72727MEDIUM4.8Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged us...
CVE-2026-71577MEDIUM6.3A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now