2026 CVE Vulnerabilities

49,581 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-40977MEDIUM6.7When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file'...
CVE-2026-7183MEDIUM5.5A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMess...
CVE-2026-7179MEDIUM5.3A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_nul...
CVE-2026-5362MEDIUM5.4An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed...
CVE-2026-29971MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. U...
CVE-2026-7150MEDIUM6.3A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the ...
CVE-2026-7148MEDIUM6.3A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Execut...
CVE-2026-40970MEDIUM6.8When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verificat...
CVE-2026-35902MEDIUM6.2The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication att...
CVE-2026-35901MEDIUM4.4A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attac...
CVE-2026-7145MEDIUM5.4A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/C...
CVE-2026-7144MEDIUM4.3A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown functi...
CVE-2026-7143MEDIUM6.3A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown funct...
CVE-2026-31691MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: igb: remove napi_synchronize() in igb_down() When ...
CVE-2026-31689MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc()...
CVE-2026-31687MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Comm...
CVE-2026-7142MEDIUM6.3A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the f...
CVE-2026-7141MEDIUM5.6A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v...
CVE-2026-38936MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php v...
CVE-2026-38935MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the do...
CVE-2026-30462MEDIUM4.3A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a dire...
CVE-2026-30346MEDIUM4.3An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to ...
CVE-2026-7135MEDIUM5.3A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is ...
CVE-2026-7134MEDIUM4.7A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of th...
CVE-2026-41467MEDIUM5.4ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionali...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now