2026 CVE Vulnerabilities

67,269 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-94393MEDIUM6.4When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without prope...
CVE-2026-94387MEDIUM5.4Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_v...
CVE-2026-94382MEDIUM4.2Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-...
CVE-2026-93884——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-88807HIGH8.9A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject cod...
CVE-2026-88806HIGH7.5A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing th...
CVE-2026-85220LOW3.7A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Deni...
CVE-2026-94383HIGH8.6The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file ext...
CVE-2026-94381HIGH8.7MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API...
CVE-2026-94379MEDIUM6.9The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-cr...
CVE-2026-94374HIGH8.3MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event mode...
CVE-2026-94373MEDIUM6.3MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The Cont...
CVE-2026-94372MEDIUM6.3MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP ...
CVE-2026-94216MEDIUM4.3A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability ...
CVE-2026-94214MEDIUM4.3A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affe...
CVE-2026-94211LOW2.4A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of th...
CVE-2026-84285HIGH8.8An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker...
CVE-2026-94368HIGH7.1A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object ...
CVE-2026-94210LOW3.5A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the...
CVE-2026-91867MEDIUM4.3When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server tha...
CVE-2026-91866HIGH7.5A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work...
CVE-2026-91865HIGH7.5A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentia...
CVE-2026-91864HIGH7.5A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into me...
CVE-2026-91863HIGH7.5A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and ex...
CVE-2026-89139HIGH8.7Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a comput...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now