2026 CVE Vulnerabilities

45,152 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8059MEDIUM6.1IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site script...
CVE-2026-7253MEDIUM6IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send ...
CVE-2026-54267MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54266MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54265MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-54264MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-53655MEDIUM5.5node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= recor...
CVE-2026-53550MEDIUM5.3js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithm...
CVE-2026-52725MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50557MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-41047MEDIUM5.5Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacke...
CVE-2026-12725MEDIUM5.9A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of...
CVE-2026-12549MEDIUM4.8The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a gene...
CVE-2026-12479MEDIUM6.1A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method ...
CVE-2026-11943MEDIUM4.8Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on i...
CVE-2026-11942MEDIUM4.8Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation...
CVE-2026-11372MEDIUM5.4IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an...
CVE-2026-9162MEDIUM4.3Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached ...
CVE-2026-9029MEDIUM5.4A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer ...
CVE-2026-7167MEDIUM6.9The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process,...
CVE-2026-6673MEDIUM6.4Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlas...
CVE-2026-6062MEDIUM6.4Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel o...
CVE-2026-5139MEDIUM5.4Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administra...
CVE-2026-56450MEDIUM5.1AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reac...
CVE-2026-10601MEDIUM4.3A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach uni...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now