2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-11388MEDIUM6.9Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Conn...
CVE-2026-86062MEDIUM6.1LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieva...
CVE-2026-85725MEDIUM5.9LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwo...
CVE-2026-85709MEDIUM5.3LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Py...
CVE-2026-84301MEDIUM6.3FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios...
CVE-2026-83602MEDIUM6.5Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api...
CVE-2026-83601MEDIUM6.5Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENS...
CVE-2026-83600MEDIUM6.5Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART ...
CVE-2026-76805MEDIUM5.3Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path ...
CVE-2026-76804MEDIUM5.5Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loadi...
CVE-2026-76803MEDIUM5.3Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript...
CVE-2026-76802MEDIUM4.7Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading b...
CVE-2026-56682MEDIUM5.39Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without ...
CVE-2026-95805MEDIUM5.3A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action t...
CVE-2026-90462MEDIUM5.4A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `...
CVE-2026-88010MEDIUM6.3Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewar...
CVE-2026-86805MEDIUM6.3A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versio...
CVE-2026-81886MEDIUM5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit ...
CVE-2026-81885MEDIUM5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation f...
CVE-2026-81882MEDIUM6.1radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property...
CVE-2026-81881MEDIUM4.4radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift fi...
CVE-2026-81880MEDIUM5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred...
CVE-2026-81879MEDIUM6.1radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM han...
CVE-2026-81878MEDIUM5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecod...
CVE-2026-79913MEDIUM6.5Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side requ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now