2026 CVE Vulnerabilities

48,527 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-42572MEDIUM6.5Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a...
CVE-2026-41888MEDIUM6.5Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELE...
CVE-2026-45448MEDIUM4.3CWE-601 URL redirection to untrusted site ('open redirect')
CVE-2026-44514MEDIUM6.5Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoi...
CVE-2026-44312MEDIUM5.8css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allo...
CVE-2026-20210MEDIUM5.4A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r...
CVE-2026-20209MEDIUM5.4A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r...
CVE-2026-42597MEDIUM5.9Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/c...
CVE-2026-42593MEDIUM5.3Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoff...
CVE-2026-42592MEDIUM5.3Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, che...
CVE-2026-42159MEDIUM5.4Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-44374MEDIUM4.3Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints ...
CVE-2026-44371MEDIUM5.3Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted ...
CVE-2026-44308MEDIUM6.3Spring Cloud AWS simplifies using AWS managed services in a Spring and Spring Boot applications. From 3.0.0 to 4.0.1, pp...
CVE-2026-41933MEDIUM6.9Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attac...
CVE-2026-41932MEDIUM6.1Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::...
CVE-2026-24711MEDIUM5.3Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
CVE-2026-24710MEDIUM6.1Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
CVE-2026-21730MEDIUM6.1Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unaut...
CVE-2026-6575MEDIUM4.3Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which cau...
CVE-2026-6478MEDIUM6.5Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover us...
CVE-2026-6474MEDIUM4.3Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server...
CVE-2026-6472MEDIUM5.4Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to...
CVE-2026-1630MEDIUM5.1WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can sen...
CVE-2026-6008MEDIUM6.8Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Pu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now