2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-18719MEDIUM6.3A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the compo...
CVE-2026-58045MEDIUM6.2A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:z...
CVE-2026-58042MEDIUM5.9A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Rec...
CVE-2026-58041MEDIUM5.3A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to cont...
CVE-2026-66325MEDIUM6.1Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin...
CVE-2026-66322MEDIUM5.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne...
CVE-2026-66317MEDIUM5.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a n...
CVE-2026-66316MEDIUM5.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne...
CVE-2026-66314MEDIUM5.3Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to ...
CVE-2026-66313MEDIUM6.8Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-66311MEDIUM6.2Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-65804MEDIUM6.1Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized atta...
CVE-2026-11835MEDIUM5.6Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateRese...
CVE-2026-67673MEDIUM4.6A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is...
CVE-2026-69248MEDIUM6.9cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0,...
CVE-2026-67617MEDIUM4.8Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al...
CVE-2026-67616MEDIUM5.3Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoi...
CVE-2026-48115MEDIUM6.3Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but...
CVE-2026-46714MEDIUM5.1Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a...
CVE-2026-69245MEDIUM6.5Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of ...
CVE-2026-69243MEDIUM6.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were v...
CVE-2026-52520MEDIUM5.4Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/...
CVE-2026-49132MEDIUM5.4OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec...
CVE-2026-49131MEDIUM5.4OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir...
CVE-2026-48061MEDIUM5.9Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now