2026 CVE Vulnerabilities

48,535 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8496MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar in...
CVE-2026-42580MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's c...
CVE-2026-41255MEDIUM6.1CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5...
CVE-2026-33584MEDIUM5.3Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensit...
CVE-2026-30904MEDIUM4.3Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a...
CVE-2026-22677MEDIUM6.5Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authent...
CVE-2026-0256MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticat...
CVE-2026-0249MEDIUM6.5Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacke...
CVE-2026-0248MEDIUM5.9An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attack...
CVE-2026-0245MEDIUM5.5Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configura...
CVE-2026-0242MEDIUM6.1A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL c...
CVE-2026-0239MEDIUM6.5An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with net...
CVE-2026-0235MEDIUM4.7A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to b...
CVE-2026-44581MEDIUM4.7Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Rou...
CVE-2026-44580MEDIUM6.1Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applica...
CVE-2026-44003MEDIUM5.8vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization tha...
CVE-2026-44002MEDIUM5.8vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper ...
CVE-2026-44577MEDIUM5.9Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when se...
CVE-2026-44576MEDIUM5.4Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applica...
CVE-2026-2695MEDIUM6.3A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premi...
CVE-2026-8367MEDIUM5.3aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (...
CVE-2026-45028MEDIUM6.1Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and inte...
CVE-2026-44665MEDIUM6.1fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process ent...
CVE-2026-44664MEDIUM6.1fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in...
CVE-2026-44572MEDIUM5.9Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an exte...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now