2026 CVE Vulnerabilities

48,075 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-47273MEDIUM6.5pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath ...
CVE-2026-47271MEDIUM5.1pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, src/mem.c implemented...
CVE-2026-44681MEDIUM6.1Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated...
CVE-2026-42877MEDIUM5.4FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scriptin...
CVE-2026-8716MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, an...
CVE-2026-6713MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, an...
CVE-2026-5296MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 1...
CVE-2026-45046MEDIUM5.5Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph implements logging levels that determine wha...
CVE-2026-42879MEDIUM6.3FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricte...
CVE-2026-42878MEDIUM5.3FacturaScripts is an open source accounting and invoicing software. Prior to v2026, an unauthenticated information discl...
CVE-2026-2601MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 1...
CVE-2026-1402MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, an...
CVE-2026-4392MEDIUM6.9A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown processing of the compo...
CVE-2026-4391MEDIUM6.9A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code o...
CVE-2026-4390MEDIUM5.4A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function process_resend_queue of the...
CVE-2026-48148MEDIUM5.3Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts ...
CVE-2026-48147MEDIUM6.5Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages...
CVE-2026-48128MEDIUM5.1Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a qu...
CVE-2026-46424MEDIUM4.2Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/publ...
CVE-2026-45719MEDIUM6.5Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation ...
CVE-2026-45718MEDIUM5.4Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:source...
CVE-2026-45081MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could a...
CVE-2026-42328MEDIUM6.2go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec ...
CVE-2026-38808MEDIUM5.3SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the Prod...
CVE-2026-49054MEDIUM4.3Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Cont...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now