2026 CVE Vulnerabilities

45,571 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-0267MEDIUM5.5An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn...
CVE-2026-0266MEDIUM4.8A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated admi...
CVE-2026-50127MEDIUM5.9Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did...
CVE-2026-46683MEDIUM6.9Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0...
CVE-2026-45106MEDIUM4.6Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and...
CVE-2026-50639MEDIUM6.5Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd pr...
CVE-2026-11626MEDIUM5.4CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalation vulnerability, w...
CVE-2026-10740MEDIUM6.9Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote...
CVE-2026-50569MEDIUM4.3Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-50565MEDIUM4.9Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-46642MEDIUM6.1draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a crafted .drawio file ca...
CVE-2026-46618MEDIUM6.9Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-20260MEDIUM4.3In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker coul...
CVE-2026-20259MEDIUM5.5In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.1...
CVE-2026-20258MEDIUM5.4In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25...
CVE-2026-20257MEDIUM5.7In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25...
CVE-2026-20256MEDIUM5.7In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25...
CVE-2026-20255MEDIUM5.7In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25...
CVE-2026-20254MEDIUM5.7In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25...
CVE-2026-11596MEDIUM4.7In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an au...
CVE-2026-46616MEDIUM6.1Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to s...
CVE-2026-46609MEDIUM4.6Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML int...
CVE-2026-53698MEDIUM6.5Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.
CVE-2026-53693MEDIUM6.9A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering pa...
CVE-2026-49760MEDIUM5.5Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulner...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now