2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-81878MEDIUM5.5radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecod...
CVE-2026-79913MEDIUM6.5Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side requ...
CVE-2026-79312MEDIUM6.8webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the re...
CVE-2026-75517MEDIUM6.5Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use...
CVE-2026-75511MEDIUM5.3Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URL...
CVE-2026-75510MEDIUM5.1Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox ...
CVE-2026-95754MEDIUM6.9In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentica...
CVE-2026-95703MEDIUM5.1In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem pro...
CVE-2026-95701MEDIUM5.1In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path co...
CVE-2026-95698MEDIUM5.3The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organizatio...
CVE-2026-95697MEDIUM5.3MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to t...
CVE-2026-95693MEDIUM5.3In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), ...
CVE-2026-95685MEDIUM5.3MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allo...
CVE-2026-95683MEDIUM5.3In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrich...
CVE-2026-95501MEDIUM4.3A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the ...
CVE-2026-94570MEDIUM5.9SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decod...
CVE-2026-93344MEDIUM6.5MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_...
CVE-2026-79315MEDIUM4.7A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request U...
CVE-2026-65129MEDIUM6.7NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate v...
CVE-2026-65127MEDIUM4.1NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive ...
CVE-2026-65126MEDIUM5NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement o...
CVE-2026-65125MEDIUM6.6NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a ...
CVE-2026-65124MEDIUM5.9NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A su...
CVE-2026-65117MEDIUM5NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded pa...
CVE-2026-65115MEDIUM6.5NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now