2026 CVE Vulnerabilities

48,280 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-48710MEDIUM6.5Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not valida...
CVE-2026-44903MEDIUM6.1Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the ...
CVE-2026-44788MEDIUM6.5SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a pa...
CVE-2026-44213MEDIUM6.5The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Inst...
CVE-2026-42015MEDIUM5.3A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allow...
CVE-2026-9583MEDIUM4.3A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This imp...
CVE-2026-9582MEDIUM4.3A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Thi...
CVE-2026-9581MEDIUM6.3A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/co...
CVE-2026-9579MEDIUM6.3A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/logi...
CVE-2026-48593MEDIUM5.9Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modules) allows memory e...
CVE-2026-48592MEDIUM5.3Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthor...
CVE-2026-47672MEDIUM6.5epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any networ...
CVE-2026-45413MEDIUM6.9MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes...
CVE-2026-45412MEDIUM6.3MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated u...
CVE-2026-44899MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the...
CVE-2026-44898MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-c...
CVE-2026-44897MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the openin...
CVE-2026-44896MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py...
CVE-2026-44844MEDIUM6.3eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well...
CVE-2026-44836MEDIUM6.5view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3...
CVE-2026-44708MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline m...
CVE-2026-44443MEDIUM4.8Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level varia...
CVE-2026-42337MEDIUM5.3MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vul...
CVE-2026-42336MEDIUM5.1MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forge...
CVE-2026-42335MEDIUM6.3MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-s...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now