2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-94413MEDIUM6.5jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve ...
CVE-2026-91167MEDIUM6Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/...
CVE-2026-91166MEDIUM5.7Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path i...
CVE-2026-91164MEDIUM4.3Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authent...
CVE-2026-82165MEDIUM5.5Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vu...
CVE-2026-82163MEDIUM5.5Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. ...
CVE-2026-63329MEDIUM4.9Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate...
CVE-2026-61749MEDIUM6.5InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or...
CVE-2026-61748MEDIUM4.3InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and Labe...
CVE-2026-61747MEDIUM4.3InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mappin...
CVE-2026-61746MEDIUM5.3InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and Pl...
CVE-2026-61744MEDIUM6.5InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesi...
CVE-2026-92382MEDIUM4.1An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves ...
CVE-2026-69190MEDIUM6.3Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for s...
CVE-2026-61745MEDIUM4.3InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in...
CVE-2026-61612MEDIUM5.7CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerU...
CVE-2026-55473MEDIUM6HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetada...
CVE-2026-48974MEDIUM5.4HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberA...
CVE-2026-77582MEDIUM6.9Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing di...
CVE-2026-77561MEDIUM5.3Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST...
CVE-2026-63373MEDIUM4.2draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler...
CVE-2026-63334MEDIUM6.8draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DR...
CVE-2026-62987MEDIUM5.8Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48...
CVE-2026-62866MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1...
CVE-2026-62370MEDIUM6.5KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now