2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-59168MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1...
CVE-2026-58504MEDIUM6.1draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a cra...
CVE-2026-17051MEDIUM6The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ip...
CVE-2026-17050MEDIUM5.7The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicat...
CVE-2026-88978MEDIUM4.3Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, t...
CVE-2026-77165MEDIUM6.5File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recov...
CVE-2026-63342MEDIUM6.3Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ap...
CVE-2026-61681MEDIUM4.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, th...
CVE-2026-36472MEDIUM5.2CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allow...
CVE-2026-36471MEDIUM5.8Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote att...
CVE-2026-36470MEDIUM5.8CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied i...
CVE-2026-36468MEDIUM6.1Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitra...
CVE-2026-93339MEDIUM5.4Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that all...
CVE-2026-82355MEDIUM4.2When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airf...
CVE-2026-75158MEDIUM4.3Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting ...
CVE-2026-61630MEDIUM4.2nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enable...
CVE-2026-55625MEDIUM4.9GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/adm...
CVE-2026-54584MEDIUM5.3mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including w...
CVE-2026-52743MEDIUM4.3GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a ...
CVE-2026-52742MEDIUM5.1GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical...
CVE-2026-52740MEDIUM5.3GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names ca...
CVE-2026-94394MEDIUM6.3When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall ...
CVE-2026-94393MEDIUM6.4When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without prope...
CVE-2026-94387MEDIUM5.4Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_v...
CVE-2026-94382MEDIUM4.2Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now