2026 CVE Vulnerabilities

50,404 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6190MEDIUM6.3A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown functio...
CVE-2026-39940MEDIUM5.3ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCR...
CVE-2026-33555MEDIUM5.8An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches ...
CVE-2026-30812MEDIUM5.4Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event c...
CVE-2026-30811MEDIUM6.5Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affe...
CVE-2026-29628MEDIUM6.2A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause...
CVE-2026-31428MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: fix uninitialized padding...
CVE-2026-31427MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitializ...
CVE-2026-31425MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rds: ib: reject FRMR registration before IB connect...
CVE-2026-31424MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_che...
CVE-2026-31423MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min...
CVE-2026-31422MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: fix NULL pointer dereference o...
CVE-2026-31421MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL pointer dereference on ...
CVE-2026-31420MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bridge: mrp: reject zero test interval to avoid OOM...
CVE-2026-31418MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in m...
CVE-2026-31416MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink heade...
CVE-2026-31415MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid overflows in ip6_datagram_send_ctl() Y...
CVE-2026-2728MEDIUM4.8LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig pa...
CVE-2026-35565MEDIUM5.4Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6...
CVE-2026-0232MEDIUM4.4A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows admin...
CVE-2026-34866MEDIUM5.1Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect av...
CVE-2026-21013MEDIUM5.5Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive in...
CVE-2026-21011MEDIUM6.8Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attacker...
CVE-2026-21009MEDIUM6.8Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass ...
CVE-2026-21008MEDIUM6.5Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitiv...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now