2026 CVE Vulnerabilities

47,701 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1871MEDIUM6.5TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validat...
CVE-2026-9590MEDIUM5.3Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an aut...
CVE-2026-9522MEDIUM5.4Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authe...
CVE-2026-7299MEDIUM5.4Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them i...
CVE-2026-49753MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allow...
CVE-2026-45684MEDIUM5.3OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0...
CVE-2026-45682MEDIUM5.5OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45681MEDIUM5.9OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45679MEDIUM6.5OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45676MEDIUM5.5OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45554MEDIUM5.3NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static asse...
CVE-2026-45080MEDIUM6.9Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access co...
CVE-2026-38978MEDIUM5.3transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.
CVE-2026-35718MEDIUM6.5A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allow...
CVE-2026-35716MEDIUM6.3A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authe...
CVE-2026-34460MEDIUM5.4NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not ...
CVE-2026-7313MEDIUM4.9CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 ...
CVE-2026-49782MEDIUM5.4Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Acce...
CVE-2026-43965MEDIUM5.6Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/pa...
CVE-2026-42795MEDIUM5.1Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in th...
CVE-2026-41918MEDIUM5.9A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applicatio...
CVE-2026-35717MEDIUM6.3A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows auth...
CVE-2026-32685MEDIUM4.6Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write...
CVE-2026-32250MEDIUM4.3NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovere...
CVE-2026-28116MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Pr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now