2026 CVE Vulnerabilities

46,924 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-47106MEDIUM5.4Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerabili...
CVE-2026-32856MEDIUM6.1Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerab...
CVE-2026-40639MEDIUM5.7Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical...
CVE-2026-39170MEDIUM6.3SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.
CVE-2026-36798MEDIUM6.5Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple stack overflows in the formSet...
CVE-2026-36778MEDIUM4.9Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in...
CVE-2026-36777MEDIUM6.5Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in...
CVE-2026-36773MEDIUM6.5Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in...
CVE-2026-36772MEDIUM6.5Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in...
CVE-2026-36728MEDIUM5.4A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allow...
CVE-2026-36726MEDIUM5.3An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthe...
CVE-2026-36725MEDIUM6.1A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 a...
CVE-2026-36724MEDIUM6.5An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers...
CVE-2026-36722MEDIUM5.4An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows atta...
CVE-2026-44275MEDIUM6.3Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link...
CVE-2026-41116MEDIUM6.3Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link...
CVE-2026-34705MEDIUM5.5InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead t...
CVE-2026-34704MEDIUM5.5InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could r...
CVE-2026-34703MEDIUM5.5InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could r...
CVE-2026-34694MEDIUM4.8Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting ...
CVE-2026-28237MEDIUM5.5Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially lead...
CVE-2026-0466MEDIUM5.5Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memor...
CVE-2026-9210MEDIUM4.5Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-50507MEDIUM6.8Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security f...
CVE-2026-49958MEDIUM5Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the g...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now