2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-93015MEDIUM6.3BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream...
CVE-2026-93013MEDIUM4.3RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadat...
CVE-2026-92881MEDIUM4.3A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory ...
CVE-2026-86862MEDIUM6.5pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbn...
CVE-2026-86861MEDIUM5.9pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested pat...
CVE-2026-86000MEDIUM5.3Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src...
CVE-2026-85999MEDIUM5.3Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soups...
CVE-2026-85718MEDIUM5.9The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-85717MEDIUM6.8The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-81868MEDIUM6.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-76781MEDIUM5.5A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL po...
CVE-2026-75523MEDIUM5.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-92880MEDIUM6.3A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/c...
CVE-2026-85078MEDIUM6.5Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does...
CVE-2026-81447MEDIUM6.8Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerabil...
CVE-2026-63461MEDIUM5.3Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and fac...
CVE-2026-61793MEDIUM6.9Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthen...
CVE-2026-92973MEDIUM6.1ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that f...
CVE-2026-92963MEDIUM5.3vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL gl...
CVE-2026-92952MEDIUM6.8vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. ...
CVE-2026-92949MEDIUM4vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowin...
CVE-2026-92945MEDIUM4.2vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix...
CVE-2026-92936MEDIUM5.8vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting....
CVE-2026-92933MEDIUM5.8vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the...
CVE-2026-92879MEDIUM4.3A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now