2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-65112MEDIUM6.5NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource ...
CVE-2026-95682MEDIUM4.8MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org orga...
CVE-2026-95679MEDIUM6.9MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build...
CVE-2026-95674MEDIUM5.3In MISP, the queryEnrichment method in EventsController.php accepted a module name parameter and iterated over the list ...
CVE-2026-95671MEDIUM5.3In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element cap...
CVE-2026-95667MEDIUM6.9The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_ins...
CVE-2026-95666MEDIUM4.3Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length o...
CVE-2026-95665MEDIUM5.1MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. Th...
CVE-2026-95396MEDIUM4.3A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unk...
CVE-2026-93343MEDIUM6.5MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_ven...
CVE-2026-93342MEDIUM5.4MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate...
CVE-2026-93341MEDIUM4.3MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refu...
CVE-2026-95661MEDIUM5.1MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes v...
CVE-2026-95659MEDIUM4.8MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. T...
CVE-2026-95658MEDIUM6.9MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list....
CVE-2026-95273MEDIUM4.3A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of ...
CVE-2026-63279MEDIUM5.4LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an ...
CVE-2026-63278MEDIUM6.7URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information c...
CVE-2026-63276MEDIUM5.4LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and C...
CVE-2026-63275MEDIUM5.4LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hin...
CVE-2026-63274MEDIUM5.4LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of ...
CVE-2026-63273MEDIUM5.4LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The leng...
CVE-2026-63272MEDIUM5.4LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a...
CVE-2026-95623MEDIUM5.6The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the in...
CVE-2026-92882MEDIUM5.3Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now