2026 CVE Vulnerabilities

48,542 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8200MEDIUM5.3When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc...
CVE-2026-44352MEDIUM5.3Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-44347MEDIUM6.5Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate ...
CVE-2026-44341MEDIUM5.3GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthentica...
CVE-2026-44245MEDIUM6.1Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directiv...
CVE-2026-42157MEDIUM5.1Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-44306MEDIUM5.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the f...
CVE-2026-44305MEDIUM6.8Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP aut...
CVE-2026-44259MEDIUM4.6efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME t...
CVE-2026-42545MEDIUM5.9Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI ap...
CVE-2026-41195MEDIUM5mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package sourc...
CVE-2026-33570MEDIUM6.9PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normall...
CVE-2026-35504MEDIUM5.5PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communicati...
CVE-2026-8052MEDIUM6HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as ...
CVE-2026-6959MEDIUM6HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host a...
CVE-2026-44874MEDIUM4.9A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remo...
CVE-2026-44873MEDIUM5.4A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their a...
CVE-2026-44223MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidd...
CVE-2026-44217MEDIUM6.6sse-channel is an SSE-implementation which can be used to any node.js http request/response stream. Prior to 4.0.1, impl...
CVE-2026-42445MEDIUM5.5NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability ex...
CVE-2026-42444MEDIUM5.5NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists i...
CVE-2026-42443MEDIUM5.5NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UF...
CVE-2026-42442MEDIUM5.5NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the U...
CVE-2026-42355MEDIUM5.5NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability ex...
CVE-2026-42338MEDIUM6.1ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.gr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now