2026 CVE Vulnerabilities

47,574 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-49940MEDIUM6.5Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Ar...
CVE-2026-46739MEDIUM5.3Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colon...
CVE-2026-7774MEDIUM6.9tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names,...
CVE-2026-45287MEDIUM5.5OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1...
CVE-2026-41178MEDIUM5.3OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and ...
CVE-2026-40930MEDIUM5.4LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. I...
CVE-2026-10815MEDIUM6.3A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. Thi...
CVE-2026-47707MEDIUM5.3Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter ext...
CVE-2026-47706MEDIUM5.3Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter ext...
CVE-2026-45739MEDIUM4.3Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled Gra...
CVE-2026-36180MEDIUM4.6A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only pr...
CVE-2026-36178MEDIUM4.6The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configu...
CVE-2026-36175MEDIUM6.8An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and ...
CVE-2026-36174MEDIUM4.6GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations t...
CVE-2026-10864MEDIUM4.3A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influenc...
CVE-2026-10860MEDIUM6.5A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used th...
CVE-2026-10811MEDIUM6.3A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is...
CVE-2026-43926MEDIUM6.3FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset conf...
CVE-2026-40605MEDIUM5.7Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal...
CVE-2026-10861MEDIUM6.1An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_lo...
CVE-2026-10856MEDIUM6.1A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a loc...
CVE-2026-10855MEDIUM4.3An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template i...
CVE-2026-10854MEDIUM4.3A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxi...
CVE-2026-10810MEDIUM4.3A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the ...
CVE-2026-10809MEDIUM6.3A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now