2026 CVE Vulnerabilities

49,799 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-22748MEDIUM6.5Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusRea...
CVE-2026-40451MEDIUM6.1DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which all...
CVE-2026-6835MEDIUM6.1The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to ...
CVE-2026-6416MEDIUM4.9Tanium addressed an uncontrolled resource consumption vulnerability in Interact.
CVE-2026-6386MEDIUM6.2In order to apply a particular protection key to an address range, the kernel must update the corresponding page table e...
CVE-2026-41457MEDIUM6.9OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that a...
CVE-2026-41136MEDIUM5.3free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generati...
CVE-2026-41131MEDIUM5OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, mode...
CVE-2026-41130MEDIUM5.5Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through ...
CVE-2026-41129MEDIUM5.5Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9...
CVE-2026-41128MEDIUM5.3Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint...
CVE-2026-41127MEDIUM6.5BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows vie...
CVE-2026-41126MEDIUM4.3BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/...
CVE-2026-40343MEDIUM5.8free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core...
CVE-2026-5512MEDIUM4.3An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacke...
CVE-2026-41063MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSa...
CVE-2026-41062MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in comm...
CVE-2026-41061MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/vide...
CVE-2026-41060MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/fun...
CVE-2026-41055MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks p...
CVE-2026-40935MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA l...
CVE-2026-40929MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mu...
CVE-2026-40928MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/...
CVE-2026-6830MEDIUM4.8nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi...
CVE-2026-6829MEDIUM6.3nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or chan...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now