2026 CVE Vulnerabilities

48,008 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10116MEDIUM4.3A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in ...
CVE-2026-10115MEDIUM4.3A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler....
CVE-2026-10114MEDIUM4.3A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the lib...
CVE-2026-10113MEDIUM4.3A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality in the libr...
CVE-2026-48840MEDIUM5.3Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of unini...
CVE-2026-9831MEDIUM6.3A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-c...
CVE-2026-48811MEDIUM4.3FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a ...
CVE-2026-48810MEDIUM4.3FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating...
CVE-2026-45294MEDIUM5.3FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset ...
CVE-2026-44640MEDIUM4.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_...
CVE-2026-44287MEDIUM6.3FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/...
CVE-2026-42500MEDIUM5.3Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid ...
CVE-2026-34127MEDIUM4.8A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG...
CVE-2026-49386MEDIUM6.5In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles ...
CVE-2026-49385MEDIUM6.5In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service account...
CVE-2026-49384MEDIUM6.1In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
CVE-2026-49381MEDIUM4.8In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
CVE-2026-49380MEDIUM6.1In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
CVE-2026-49379MEDIUM6.5In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
CVE-2026-49378MEDIUM4.3In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
CVE-2026-49377MEDIUM4.3In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
CVE-2026-49376MEDIUM6.5In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
CVE-2026-49375MEDIUM6.1In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
CVE-2026-49369MEDIUM4.3In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
CVE-2026-49368MEDIUM5.4In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now