2026 CVE Vulnerabilities

47,686 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10624MEDIUM4.3A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unk...
CVE-2026-8035MEDIUM5.5Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service ...
CVE-2026-5074MEDIUM6.5The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_priv...
CVE-2026-48682MEDIUM5.9FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packe...
CVE-2026-48597MEDIUM5.9Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via at...
CVE-2026-48595MEDIUM5.9Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party ori...
CVE-2026-40181MEDIUM6.1React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to th...
CVE-2026-35049MEDIUM6.5wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted m...
CVE-2026-33553MEDIUM6.1Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.
CVE-2026-33245MEDIUM4.7React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Co...
CVE-2026-30586MEDIUM6.1Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information v...
CVE-2026-10702MEDIUM4.3JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
CVE-2026-10616MEDIUM4.3A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTo...
CVE-2026-49943MEDIUM6.3CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matchi...
CVE-2026-42073MEDIUM6.5OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0...
CVE-2026-40713MEDIUM6.1Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenti...
CVE-2026-40571MEDIUM5.3NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.ph...
CVE-2026-40314MEDIUM6.9NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php...
CVE-2026-35447MEDIUM5.3NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php...
CVE-2026-35443MEDIUM5.3NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext....
CVE-2026-33244MEDIUM5.4React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabl...
CVE-2026-1871MEDIUM6.5TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validat...
CVE-2026-9590MEDIUM5.3Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an aut...
CVE-2026-9522MEDIUM5.4Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authe...
CVE-2026-7299MEDIUM5.4Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now