2026 CVE Vulnerabilities

47,636 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-47306MEDIUM6.1Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This iss...
CVE-2026-10305MEDIUM6.1Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: be...
CVE-2026-50212MEDIUM6.5Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user...
CVE-2026-50206MEDIUM6.8Incoming VPN network profile settings fail to process special characters safely, enabling command injection via maliciou...
CVE-2026-49204MEDIUM6.5Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
CVE-2026-49192MEDIUM5.4The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware seri...
CVE-2026-50219MEDIUM5.9libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars...
CVE-2026-10805MEDIUM6.7A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient ba...
CVE-2026-44917MEDIUM4.9OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron...
CVE-2026-10597MEDIUM6.9OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote a...
CVE-2026-8653MEDIUM6.5The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in ...
CVE-2026-7764MEDIUM6.8An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versio...
CVE-2026-8722MEDIUM6.5Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked fo...
CVE-2026-10775MEDIUM5.3A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_h...
CVE-2026-43924MEDIUM4.8FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module doe...
CVE-2026-40495MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system v...
CVE-2026-37700MEDIUM4.1Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via t...
CVE-2026-26825MEDIUM5.3A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reacha...
CVE-2026-26824MEDIUM6.5libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory al...
CVE-2026-45702MEDIUM5.5OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-45614MEDIUM4.7OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-42840MEDIUM5.1An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and...
CVE-2026-42839MEDIUM4.8An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, ...
CVE-2026-26379MEDIUM6.5Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configura...
CVE-2026-26378MEDIUM5.4Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now