2026 CVE Vulnerabilities

45,452 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-9641MEDIUM5.3Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default alg...
CVE-2026-5792MEDIUM6.5Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Market...
CVE-2026-53568MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerab...
CVE-2026-50560MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50090MEDIUM6.1The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due ...
CVE-2026-50089MEDIUM6.1The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redire...
CVE-2026-50088MEDIUM4.7The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara...
CVE-2026-50087MEDIUM6.1The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an inst...
CVE-2026-50084MEDIUM6.5The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to...
CVE-2026-50082MEDIUM5.3The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the att...
CVE-2026-50026MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in...
CVE-2026-50020MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50009MEDIUM4.8Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,...
CVE-2026-47190MEDIUM4.4IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM c...
CVE-2026-47182MEDIUM5.3Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private fi...
CVE-2026-46690MEDIUM5.8unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-v...
CVE-2026-44976MEDIUM5.3Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboard...
CVE-2026-44975MEDIUM5.3Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can res...
CVE-2026-44967MEDIUM5.3OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/m...
CVE-2026-44208MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "su...
CVE-2026-44207MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows a...
CVE-2026-44206MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possi...
CVE-2026-8694MEDIUM5.3Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attack...
CVE-2026-53722MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not vali...
CVE-2026-47739MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possibl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now