2026 CVE Vulnerabilities

45,449 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-52721MEDIUM5.3Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trig...
CVE-2026-52718MEDIUM6.5A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse...
CVE-2026-50892MEDIUM6.5Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows auth...
CVE-2026-50876MEDIUM5.4A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HT...
CVE-2026-49953MEDIUM6.9Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remo...
CVE-2026-39197MEDIUM6.5An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Serv...
CVE-2026-37216MEDIUM6.1Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.
CVE-2026-36933MEDIUM6.8An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code vi...
CVE-2026-36521MEDIUM6.1PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.
CVE-2026-11931MEDIUM6.8Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication tok...
CVE-2026-8358MEDIUM5.4LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document ...
CVE-2026-8356MEDIUM5.4LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a c...
CVE-2026-6047MEDIUM5.4LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred pars...
CVE-2026-6045MEDIUM5.4LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing ...
CVE-2026-6039MEDIUM5.4LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a ...
CVE-2026-49294MEDIUM6.1Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and...
CVE-2026-20262MEDIUM6.5A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r...
CVE-2026-9595MEDIUM4.3Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts...
CVE-2026-8683MEDIUM6.5Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Matterm...
CVE-2026-10634MEDIUM5.3Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_S...
CVE-2026-48969MEDIUM6.5Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
CVE-2026-34030MEDIUM6.9The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code wh...
CVE-2026-34029MEDIUM6.8The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the Sa...
CVE-2026-34028MEDIUM6.9The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not pr...
CVE-2026-34027MEDIUM5.3The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type valid...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now