2026 CVE Vulnerabilities

45,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-9692MEDIUM5.3Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id ...
CVE-2026-55392MEDIUM6.7NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size ...
CVE-2026-48937MEDIUM5.3A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This v...
CVE-2026-47833MEDIUM6.9setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A comp...
CVE-2026-48986MEDIUM4.7pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_...
CVE-2026-48985MEDIUM5.5pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, pusb_is_...
CVE-2026-48984MEDIUM4.7pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfre...
CVE-2026-56024MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue ...
CVE-2026-56022MEDIUM6.9Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, a...
CVE-2026-56021MEDIUM6.9Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due ...
CVE-2026-55205MEDIUM6.9Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oa...
CVE-2026-54106MEDIUM5.1The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-54105MEDIUM6.9The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-11982MEDIUM5.1Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages A...
CVE-2026-22551MEDIUM6.5In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r...
CVE-2026-11791MEDIUM5A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees...
CVE-2026-56009MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bri...
CVE-2026-56007MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Prod...
CVE-2026-54221MEDIUM5.1UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling ...
CVE-2026-54219MEDIUM5.1UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti...
CVE-2026-44942MEDIUM6.5A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series...
CVE-2026-42490MEDIUM6.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42489MEDIUM5.3[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-12539MEDIUM5.7Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl...
CVE-2026-12527MEDIUM6A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now