2026 CVE Vulnerabilities

45,065 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-13795MEDIUM6.5Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attack...
CVE-2026-13793MEDIUM6.5Insufficient policy enforcement in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-o...
CVE-2026-13790MEDIUM6.5Side-channel information leakage in Scroll in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cro...
CVE-2026-58450MEDIUM5.3Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthentic...
CVE-2026-58446MEDIUM6.9Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authenticat...
CVE-2026-57204MEDIUM6.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An at...
CVE-2026-10585MEDIUM5.4A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated att...
CVE-2026-9132MEDIUM6.5A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to r...
CVE-2026-9106MEDIUM5.5A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gai...
CVE-2026-11594MEDIUM6.1IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ...
CVE-2026-10562MEDIUM5.9An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of use...
CVE-2026-9002MEDIUM6.5IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to...
CVE-2026-3602MEDIUM5.5IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 1...
CVE-2026-12086MEDIUM5.5IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug...
CVE-2026-12085MEDIUM6.5IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8....
CVE-2026-11906MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2026-10546MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( ...
CVE-2026-58373MEDIUM5.3CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows aut...
CVE-2026-58369MEDIUM6.9Woodpecker before 3.15.0 registers the /api/orgs/lookup/*org_full_name endpoint without authentication middleware, and t...
CVE-2026-58174MEDIUM6.5Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but construct...
CVE-2026-58173MEDIUM6.5Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the inte...
CVE-2026-58171MEDIUM4.2Vibe-Trading before 0.1.10 constructs the swarm run directory by joining a caller-supplied run identifier onto the runs ...
CVE-2026-10655MEDIUM5.9The asynchronous SNTP client in Zephyr (subsys/net/lib/sntp/sntp.c, sntp_close_async) closed the UDP socket file descrip...
CVE-2026-48314MEDIUM6.5ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-44948MEDIUM5.3A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now