2026 CVE Vulnerabilities

48,280 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-36239MEDIUM4.3PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality
CVE-2026-44831MEDIUM5.4Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by...
CVE-2026-44214MEDIUM5.3eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsou...
CVE-2026-27331MEDIUM6.3Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-25444MEDIUM4.3Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-25426MEDIUM5.3Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectl...
CVE-2026-24520MEDIUM4.3Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2026-9572MEDIUM5.5A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample o...
CVE-2026-9568MEDIUM5A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDo...
CVE-2026-9566MEDIUM4.3A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-...
CVE-2026-7453MEDIUM5.5A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leadin...
CVE-2026-7450MEDIUM5.5A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability...
CVE-2026-48696MEDIUM6.2FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-...
CVE-2026-44776MEDIUM5.9Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do n...
CVE-2026-44775MEDIUM6.9Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [All...
CVE-2026-44749MEDIUM4.3The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request art...
CVE-2026-44707MEDIUM6.8Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability ex...
CVE-2026-41164MEDIUM4.4nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token intr...
CVE-2026-24201MEDIUM5.8NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound ...
CVE-2026-24199MEDIUM4.7NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition b...
CVE-2026-24198MEDIUM5.6NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to l...
CVE-2026-24197MEDIUM6.5NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an ...
CVE-2026-24195MEDIUM5.5NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A s...
CVE-2026-24182MEDIUM6.5NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A s...
CVE-2026-9565MEDIUM6.3A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now