2026 CVE Vulnerabilities

45,428 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10836MEDIUM5.1Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using special...
CVE-2026-0064MEDIUM5.5In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to loca...
CVE-2026-46979MEDIUM6.5Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and ...
CVE-2026-46877MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-46871MEDIUM6.5Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is...
CVE-2026-46869MEDIUM6.5Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are...
CVE-2026-46825MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-46812MEDIUM6.1Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp...
CVE-2026-46810MEDIUM6.5Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported...
CVE-2026-46790MEDIUM5.3Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup...
CVE-2026-46772MEDIUM4.7Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF ...
CVE-2026-46771MEDIUM4.1Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java...
CVE-2026-46770MEDIUM6.1Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Secu...
CVE-2026-46768MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-35291MEDIUM6.6Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that ...
CVE-2026-35261MEDIUM6.5Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp...
CVE-2026-12425MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool...
CVE-2026-12117MEDIUM4.3Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated ...
CVE-2026-12105MEDIUM6.5Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments vi...
CVE-2026-11890MEDIUM4.3Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authentica...
CVE-2026-0165MEDIUM5.7In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. T...
CVE-2026-0157MEDIUM4.3In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote i...
CVE-2026-0155MEDIUM4.3In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to rem...
CVE-2026-0144MEDIUM6.5In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This cou...
CVE-2026-0141MEDIUM4.3In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now