2026 CVE Vulnerabilities

68,738 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93456HIGH8.2django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing ...
CVE-2026-93455MEDIUM6.5django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff acc...
CVE-2026-93331HIGH7.3A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file ...
CVE-2026-93314MEDIUM6.3A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of t...
CVE-2026-93313MEDIUM6.3A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTabl...
CVE-2026-82985MEDIUM6.5The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolder...
CVE-2026-82982MEDIUM4.3The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing ...
CVE-2026-82980MEDIUM6.3Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The D...
CVE-2026-77170MEDIUM4.3The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without va...
CVE-2026-77169MEDIUM6.5A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed...
CVE-2026-77164MEDIUM6.2Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote insta...
CVE-2026-68493LOW3.1After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships ...
CVE-2026-93312MEDIUM4.3A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/J...
CVE-2026-93311MEDIUM4.3A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFun...
CVE-2026-93310MEDIUM5.3A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collect...
CVE-2026-79954HIGH8.7NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiv...
CVE-2026-93454MEDIUM5.4Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plu...
CVE-2026-93453HIGH8.3SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing u...
CVE-2026-93452HIGH7.5snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that wr...
CVE-2026-93451MEDIUM6.5snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allo...
CVE-2026-93450HIGH7.5go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serializatio...
CVE-2026-93309MEDIUM4.3A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of t...
CVE-2026-93308MEDIUM4.3A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of ...
CVE-2026-85887HIGH7.7Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose informat...
CVE-2026-85878CRITICAL9.9Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a netwo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now