2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-66832MEDIUM6.9When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app...
CVE-2026-66148MEDIUM6.3An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.10...
CVE-2026-63134MEDIUM5.4Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w...
CVE-2026-63133MEDIUM6.5Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives...
CVE-2026-48762MEDIUM5.4TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u...
CVE-2026-29035MEDIUM6.5CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that...
CVE-2026-19579MEDIUM5.4Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request ...
CVE-2026-19550MEDIUM4.3A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath...
CVE-2026-73282MEDIUM4.8In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat...
CVE-2026-73244MEDIUM5.3kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /li...
CVE-2026-73243MEDIUM5.8kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /add...
CVE-2026-73235MEDIUM6.1FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constru...
CVE-2026-73230MEDIUM5.9Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version...
CVE-2026-73229MEDIUM4.3Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's...
CVE-2026-73036MEDIUM4.6Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt...
CVE-2026-71845MEDIUM6.3A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes...
CVE-2026-71475MEDIUM5A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data ...
CVE-2026-71474MEDIUM6.3A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, whic...
CVE-2026-71468MEDIUM5.3A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly ...
CVE-2026-70339MEDIUM5.4Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-66146MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions ...
CVE-2026-73228MEDIUM5.3Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing ...
CVE-2026-73221MEDIUM5.3CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user...
CVE-2026-69117MEDIUM6.5NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only...
CVE-2026-18709MEDIUM6.4An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now