2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-18708MEDIUM6.4An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to caus...
CVE-2026-18707MEDIUM5.3An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se...
CVE-2026-18703MEDIUM4.2An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authe...
CVE-2026-18702MEDIUM6.4An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnost...
CVE-2026-18700MEDIUM6.5An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an i...
CVE-2026-18699MEDIUM6.5An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser...
CVE-2026-18698MEDIUM5.4An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag...
CVE-2026-73219MEDIUM5.3CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user...
CVE-2026-73216MEDIUM6.5Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in sr...
CVE-2026-73213MEDIUM5.8Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_tu...
CVE-2026-73212MEDIUM5.8Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_...
CVE-2026-72712MEDIUM6.5Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash ...
CVE-2026-69113MEDIUM5.4Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authentica...
CVE-2026-65680MEDIUM6.7Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to el...
CVE-2026-48790MEDIUM5.5Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the us...
CVE-2026-48411MEDIUM6.5Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-20917MEDIUM4Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Proce...
CVE-2026-20901MEDIUM4Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Sta...
CVE-2026-20712MEDIUM4Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disc...
CVE-2026-0465MEDIUM5.6A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kern...
CVE-2026-73085MEDIUM5.3Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/...
CVE-2026-73084MEDIUM6.1Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoi...
CVE-2026-73082MEDIUM5.3Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mc...
CVE-2026-72971MEDIUM5.5Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs....
CVE-2026-71390MEDIUM4CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now