2026 CVE Vulnerabilities

45,451 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-54055MEDIUM5Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability ex...
CVE-2026-50552MEDIUM6.3Koel is a free, open-source music streaming solution. Prior to version 9.7.1, Koel contains a Server-Side Request Forger...
CVE-2026-43872MEDIUM5.3Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path...
CVE-2026-42890MEDIUM4.8Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron ...
CVE-2026-42604MEDIUM6.9Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server version...
CVE-2026-53726MEDIUM6.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-53725MEDIUM5.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8...
CVE-2026-50244MEDIUM6.9The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbit...
CVE-2026-50099MEDIUM5.1During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in clearte...
CVE-2026-50008MEDIUM6.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8...
CVE-2026-47248MEDIUM6.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-47236MEDIUM4.3Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view a...
CVE-2026-42932MEDIUM6.9Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predict...
CVE-2026-41568MEDIUM6.1Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and ...
CVE-2026-10715MEDIUM5.1Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-...
CVE-2026-47225MEDIUM6Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affe...
CVE-2026-47223MEDIUM5.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6....
CVE-2026-44173MEDIUM5.3MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ...
CVE-2026-44169MEDIUM4.3MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 1...
CVE-2026-7184MEDIUM6.5Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API resp...
CVE-2026-6689MEDIUM4.3Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce Permiss...
CVE-2026-6046MEDIUM5.3Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a...
CVE-2026-47224MEDIUM4.3NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6....
CVE-2026-47222MEDIUM5.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6....
CVE-2026-3433MEDIUM4.3Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict role_u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now