2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-54355MEDIUM5.3MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML outpu...
CVE-2026-50022MEDIUM5.8Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSo...
CVE-2026-92993MEDIUM6.3A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of...
CVE-2026-92758MEDIUM5.5If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive...
CVE-2026-92757MEDIUM5.5Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may in...
CVE-2026-92756MEDIUM5.5Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this prov...
CVE-2026-54594MEDIUM5.3OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/d...
CVE-2026-54495MEDIUM4.3The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant wh...
CVE-2026-92992MEDIUM6.3A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown functio...
CVE-2026-52852MEDIUM6.5Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups a...
CVE-2026-92927MEDIUM5.3A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing o...
CVE-2026-89038MEDIUM6.2Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co...
CVE-2026-54677MEDIUM6.5Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of ...
CVE-2026-54676MEDIUM6.5Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve...
CVE-2026-54551MEDIUM4.3WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2....
CVE-2026-54546MEDIUM5CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22....
CVE-2026-44235MEDIUM6.5rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an unders...
CVE-2026-8674MEDIUM5.3Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search li...
CVE-2026-85720MEDIUM5.9The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-54587MEDIUM5.8mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE ...
CVE-2026-54586MEDIUM6mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mp...
CVE-2026-54585MEDIUM6mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did...
CVE-2026-54582MEDIUM6mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non...
CVE-2026-54576MEDIUM5.8mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used...
CVE-2026-54575MEDIUM5.8mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used ra...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now