2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-92284MEDIUM6.9Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/rep...
CVE-2026-90900MEDIUM5.3Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Stor...
CVE-2026-77421MEDIUM6.5JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's...
CVE-2026-77420MEDIUM5.5JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(Str...
CVE-2026-71462MEDIUM4.1StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. ...
CVE-2026-71461MEDIUM4.3HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated use...
CVE-2026-71460MEDIUM4.3/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_...
CVE-2026-71459MEDIUM5JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() ...
CVE-2026-71458MEDIUM5URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403...
CVE-2026-63131MEDIUM6OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could ...
CVE-2026-55632MEDIUM4.3GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompleti...
CVE-2026-52744MEDIUM5.3GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API a...
CVE-2026-88840MEDIUM5.3BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
CVE-2026-88839MEDIUM6.7BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of he...
CVE-2026-88837MEDIUM6.5BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authenticati...
CVE-2026-88835MEDIUM6.1BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap ...
CVE-2026-88831MEDIUM5.3BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the ru...
CVE-2026-86867MEDIUM6.5Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabiliti...
CVE-2026-96807MEDIUM4In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regener...
CVE-2026-96655MEDIUM4.3Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses v...
CVE-2026-96654MEDIUM6.5Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an atta...
CVE-2026-96652MEDIUM4.3Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can i...
CVE-2026-96651MEDIUM6.5Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, a...
CVE-2026-6669MEDIUM5.9Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in Pg...
CVE-2026-96674MEDIUM4.4alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now