2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-63635MEDIUM5.5OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-63420MEDIUM5.5OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-59956MEDIUM6.1OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-59181MEDIUM6.1OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-59156MEDIUM6.5OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-54147MEDIUM6.5http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvid...
CVE-2026-1037MEDIUM6.1IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro...
CVE-2026-1031MEDIUM6.1IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro...
CVE-2026-1030MEDIUM4.3IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error m...
CVE-2026-1029MEDIUM5.4IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro...
CVE-2026-1025MEDIUM6.1IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro...
CVE-2026-11537MEDIUM4.3IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the fi...
CVE-2026-10841MEDIUM4.2IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
CVE-2026-93685MEDIUM5.4A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authenti...
CVE-2026-93660MEDIUM6.5SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authe...
CVE-2026-93653MEDIUM5.5A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching t...
CVE-2026-93573MEDIUM6.5A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` ...
CVE-2026-93566MEDIUM6.5A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that include...
CVE-2026-93506MEDIUM6.3A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/...
CVE-2026-85511MEDIUM4.2A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oau...
CVE-2026-77928MEDIUM6.5ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract ...
CVE-2026-77927MEDIUM6.5ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract ...
CVE-2026-25684MEDIUM4.4A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluatio...
CVE-2026-16515MEDIUM4.7net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rul...
CVE-2026-16514MEDIUM4.3gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now