2026 CVE Vulnerabilities

48,018 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-9646MEDIUM6.1A reflected cross-site scripting issue exists in URL handling.
CVE-2026-49095MEDIUM6.5Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation....
CVE-2026-49094MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-46843MEDIUM5.3Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E...
CVE-2026-46842MEDIUM5.3Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E...
CVE-2026-46841MEDIUM5.3Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0...
CVE-2026-46830MEDIUM5.3Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1....
CVE-2026-42400MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-42399MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-42070MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in Mantis...
CVE-2026-41897MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.0.0 to 2.28.1, lack of validation of filter_target...
CVE-2026-49130MEDIUM6.9Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function ...
CVE-2026-49129MEDIUM6.9Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin...
CVE-2026-42401MEDIUM5.4Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user...
CVE-2026-33464MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-13...
CVE-2026-33463MEDIUM5.3Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclos...
CVE-2026-47335MEDIUM5.5Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notificatio...
CVE-2026-47334MEDIUM5.5Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notifi...
CVE-2026-47332MEDIUM5.5Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structu...
CVE-2026-47328MEDIUM6.1Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not ...
CVE-2026-47326MEDIUM5.5Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor not...
CVE-2026-47136MEDIUM6.9RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rus...
CVE-2026-46685MEDIUM6RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is ...
CVE-2026-46526MEDIUM5Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking ...
CVE-2026-45040MEDIUM5.3RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive inform...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now