2026 CVE Vulnerabilities

45,453 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-47244MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-47141MEDIUM6.9vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability bu...
CVE-2026-45673MEDIUM6.8Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-45536MEDIUM4Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-44205MEDIUM6.9Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user prof...
CVE-2026-41581MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Inject...
CVE-2026-28975MEDIUM6.9### Impact When `NIOHTTPRequestDecompressor` is configured with `.ratio(N)`, the decompression limit is enforced using ...
CVE-2026-28970MEDIUM6.3Programs using swift-nio is vulnerable to HTTP request smuggling and HTTP response splitting attacks, caused by insuffic...
CVE-2026-49993MEDIUM5.7Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from vers...
CVE-2026-47200MEDIUM5.3Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 ...
CVE-2026-46342MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 t...
CVE-2026-45670MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions ...
CVE-2026-45669MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to b...
CVE-2026-1836MEDIUM5.3The system stores the username and password from the login form after submitting the request. This could allow an attack...
CVE-2026-49347MEDIUM5.3Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly ...
CVE-2026-50634MEDIUM6.5A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was...
CVE-2026-50630MEDIUM6.5A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate res...
CVE-2026-50629MEDIUM5.3The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages wi...
CVE-2026-50623MEDIUM4.8An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 't...
CVE-2026-48914MEDIUM6.7A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of...
CVE-2026-11847MEDIUM5.3The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowi...
CVE-2026-11844MEDIUM6.9The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, all...
CVE-2026-12058MEDIUM5.3The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
CVE-2026-9271MEDIUM5.9Vulnerability Title
CVE-2026-12060MEDIUM6.9Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticate...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now