2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-18775MEDIUM6.3A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browse...
CVE-2026-18774MEDIUM6.3A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file ag...
CVE-2026-15920MEDIUM6.1An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(...
CVE-2026-15830MEDIUM6.9An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome...
CVE-2026-15337MEDIUM6.9An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()...
CVE-2026-24078MEDIUM6.5Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077MEDIUM6.5Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel...
CVE-2026-24076MEDIUM6.7Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-18773MEDIUM6.3A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_...
CVE-2026-10032MEDIUM6.1The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the U...
CVE-2026-67618MEDIUM6.5marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat...
CVE-2026-67196MEDIUM5.4Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in...
CVE-2026-18766MEDIUM6.3A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affect...
CVE-2026-18401MEDIUM6.9The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in S...
CVE-2026-11368MEDIUM6.5The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning chann...
CVE-2026-70368MEDIUM6.5A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m...
CVE-2026-70367MEDIUM5.4A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr...
CVE-2026-14337MEDIUM4.6Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use...
CVE-2026-63248MEDIUM6.5In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an...
CVE-2026-18809MEDIUM6.5Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153...
CVE-2026-66883MEDIUM6.3Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize modu...
CVE-2026-18772MEDIUM6.5Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data ...
CVE-2026-14465MEDIUM6.5Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ...
CVE-2026-14219MEDIUM5.4URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUM...
CVE-2026-14202MEDIUM5.3Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now