2026 CVE Vulnerabilities

48,280 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-48905MEDIUM6.1Lack of input filtering leads to an XSS vector in the HTML filter code.
CVE-2026-48903MEDIUM6.1Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
CVE-2026-48900MEDIUM4.3An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
CVE-2026-48693MEDIUM5.5FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. T...
CVE-2026-47728MEDIUM4.3Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID wi...
CVE-2026-46431MEDIUM4.3Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Orig...
CVE-2026-46430MEDIUM4.3Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Li...
CVE-2026-45836MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_...
CVE-2026-45835MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_...
CVE-2026-45834MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_...
CVE-2026-44502MEDIUM4.3Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypa...
CVE-2026-44314MEDIUM4.3Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device ...
CVE-2026-35220MEDIUM4.3Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.
CVE-2026-30895MEDIUM6.1Lack of output escaping leads to a XSS vector in the readmore links for com_content.
CVE-2026-30894MEDIUM6.1Lack of output escaping leads to a XSS vector in the content history component.
CVE-2026-25901MEDIUM6.1Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-25900MEDIUM6.1Lack of output escaping leads to a XSS vector in the feed modules.
CVE-2026-48685MEDIUM6.5FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attrib...
CVE-2026-48684MEDIUM6.5FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In ...
CVE-2026-48683MEDIUM6.5FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset p...
CVE-2026-46620MEDIUM6.5e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on c...
CVE-2026-43936MEDIUM4.3e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of...
CVE-2026-43934MEDIUM6.5e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the applicati...
CVE-2026-40564MEDIUM6.5Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Ku...
CVE-2026-38587MEDIUM4.3An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw ex...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now