2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-15915MEDIUM6.2IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of...
CVE-2026-96260MEDIUM6.5Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request ...
CVE-2026-96259MEDIUM5.5Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal...
CVE-2026-95815MEDIUM6.3OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as pub...
CVE-2026-95813MEDIUM6.1e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and co...
CVE-2026-95812MEDIUM6.1ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper functi...
CVE-2026-88020MEDIUM6.1Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability ...
CVE-2026-77425MEDIUM4.3Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:fea...
CVE-2026-76910MEDIUM5.3Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:...
CVE-2026-75101MEDIUM6An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of ...
CVE-2026-88341MEDIUM5.5A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can ...
CVE-2026-88339MEDIUM5.5A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). T...
CVE-2026-83805MEDIUM6.4Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkf...
CVE-2026-83801MEDIUM5.4Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add...
CVE-2026-79767MEDIUM5.5Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143....
CVE-2026-76717MEDIUM5.3A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive inf...
CVE-2026-76716MEDIUM5.3Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or deni...
CVE-2026-65829MEDIUM5.3MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 ...
CVE-2026-63628MEDIUM6.9mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/...
CVE-2026-63627MEDIUM6.9mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-p...
CVE-2026-91129MEDIUM5.4Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP ...
CVE-2026-89277MEDIUM5.5CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...
CVE-2026-84396MEDIUM5.5InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-s...
CVE-2026-77399MEDIUM6.5icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.fro...
CVE-2026-77272MEDIUM5.4MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now