2026 CVE Vulnerabilities

49,842 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41062MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in comm...
CVE-2026-41061MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/vide...
CVE-2026-41060MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/fun...
CVE-2026-41055MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks p...
CVE-2026-40935MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA l...
CVE-2026-40929MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mu...
CVE-2026-40928MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/...
CVE-2026-6830MEDIUM4.8nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi...
CVE-2026-6829MEDIUM6.3nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or chan...
CVE-2026-6799MEDIUM6.3A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of ...
CVE-2026-41527MEDIUM6.9KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there i...
CVE-2026-40944MEDIUM6.9Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configurati...
CVE-2026-40942MEDIUM6.3The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr...
CVE-2026-40939MEDIUM6.8The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr...
CVE-2026-1354MEDIUM6.4Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bl...
CVE-2026-6797MEDIUM5.3A vulnerability was identified in Sanluan PublicCMS up to 6.202506.d. Affected by this vulnerability is the function Zip...
CVE-2026-6796MEDIUM5.3A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file cor...
CVE-2026-40927MEDIUM5.4Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page,...
CVE-2026-40924MEDIUM6.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and...
CVE-2026-40923MEDIUM5.4Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and...
CVE-2026-35252MEDIUM6.4Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: C Oracle SSL API). Support...
CVE-2026-35248MEDIUM5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-35247MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-35244MEDIUM5.2Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Manageme...
CVE-2026-35241MEDIUM5.7Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now