2026 CVE Vulnerabilities

49,744 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41136MEDIUM5.3free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generati...
CVE-2026-41131MEDIUM5OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, mode...
CVE-2026-41130MEDIUM5.5Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through ...
CVE-2026-41129MEDIUM5.5Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9...
CVE-2026-41128MEDIUM5.3Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint...
CVE-2026-41127MEDIUM6.5BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows vie...
CVE-2026-41126MEDIUM4.3BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/...
CVE-2026-40343MEDIUM5.8free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core...
CVE-2026-5512MEDIUM4.3An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacke...
CVE-2026-41063MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSa...
CVE-2026-41062MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in comm...
CVE-2026-41061MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/vide...
CVE-2026-41060MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/fun...
CVE-2026-41055MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks p...
CVE-2026-40935MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA l...
CVE-2026-40929MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mu...
CVE-2026-40928MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/...
CVE-2026-6830MEDIUM4.8nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi...
CVE-2026-6829MEDIUM6.3nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or chan...
CVE-2026-6799MEDIUM6.3A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of ...
CVE-2026-41527MEDIUM6.9KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there i...
CVE-2026-40944MEDIUM6.9Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configurati...
CVE-2026-40942MEDIUM6.3The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr...
CVE-2026-40939MEDIUM6.8The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr...
CVE-2026-1354MEDIUM6.4Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now