2026 CVE Vulnerabilities

45,307 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-54386MEDIUM6.1marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenti...
CVE-2026-48991MEDIUM5.5XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts coul...
CVE-2026-48990MEDIUM5.3joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2026-48820MEDIUM6.3CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1...
CVE-2026-48988MEDIUM5.3markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: ...
CVE-2026-48821MEDIUM5.8Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vuln...
CVE-2026-48823MEDIUM4.8Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnera...
CVE-2026-48822MEDIUM5.8Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnera...
CVE-2026-48817MEDIUM5.3Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint...
CVE-2026-10741MEDIUM4.9Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configur...
CVE-2026-53870MEDIUM6.8Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mod...
CVE-2026-9679MEDIUM5.9Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences...
CVE-2026-9678MEDIUM5.9Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control he...
CVE-2026-7300MEDIUM6.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web In...
CVE-2026-48591MEDIUM4.8Improper Neutralization of Script in Attributes in a Web Page vulnerability in pragdave earmark allows stored cross-site...
CVE-2026-2675MEDIUM6.5Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake th...
CVE-2026-20265MEDIUM4.3In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles ...
CVE-2026-20178MEDIUM4.3A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker t...
CVE-2026-35068MEDIUM5.7Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a...
CVE-2026-20246MEDIUM6A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to e...
CVE-2026-20220MEDIUM6.3A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenti...
CVE-2026-1288MEDIUM5.5A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL...
CVE-2026-12515MEDIUM4.3A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization chec...
CVE-2026-55748MEDIUM6OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name ...
CVE-2026-48142MEDIUM6.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now