2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-11538MEDIUM5.3IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token coo...
CVE-2026-93764MEDIUM6.5Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level enc...
CVE-2026-93763MEDIUM6.5A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that...
CVE-2026-93751MEDIUM6.5uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlon...
CVE-2026-93750MEDIUM5.9http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails t...
CVE-2026-93432MEDIUM6.1A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails...
CVE-2026-92768MEDIUM5.5A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM...
CVE-2026-92747MEDIUM5A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running p...
CVE-2026-92745MEDIUM5A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process met...
CVE-2026-84992MEDIUM6.1md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt()...
CVE-2026-81182MEDIUM4.2SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a ...
CVE-2026-77396MEDIUM6.9PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser...
CVE-2026-77386MEDIUM6.5Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker cou...
CVE-2026-77385MEDIUM4.3Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core...
CVE-2026-71537MEDIUM6.5Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Se...
CVE-2026-69186MEDIUM5.3c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NS...
CVE-2026-64847MEDIUM6.8AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Pri...
CVE-2026-93579MEDIUM6.5A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, s...
CVE-2026-93534MEDIUM6.3A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file ap...
CVE-2026-93533MEDIUM6.3A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivi...
CVE-2026-93338MEDIUM5.3Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows una...
CVE-2026-91147MEDIUM5.9A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Serv...
CVE-2026-77616MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77610MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77609MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now