2026 CVE Vulnerabilities

50,562 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-40223MEDIUM5.5In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exi...
CVE-2026-40023MEDIUM5.3Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions...
CVE-2026-40021MEDIUM5.3Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLa...
CVE-2026-35594MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (Get...
CVE-2026-34477MEDIUM5.9The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna...
CVE-2026-29043MEDIUM5.5HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can t...
CVE-2026-31262MEDIUM6.1Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtai...
CVE-2026-6067MEDIUM5.5A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_...
CVE-2026-5774MEDIUM6.4Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow a...
CVE-2026-5412MEDIUM6.5In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated us...
CVE-2026-31412MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: Fix potential integer ...
CVE-2026-6042MEDIUM4.8A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/icon...
CVE-2026-33457MEDIUM6.3Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated ...
CVE-2026-33455MEDIUM6.3Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livest...
CVE-2026-6035MEDIUM4.3A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unkno...
CVE-2026-6034MEDIUM4.3A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the fi...
CVE-2026-6033MEDIUM6.3A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedet...
CVE-2026-6032MEDIUM4.3A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /chec...
CVE-2026-40212MEDIUM5.4OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console...
CVE-2026-6030MEDIUM6.3A flaw has been found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of...
CVE-2026-4432MEDIUM6.5The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_t...
CVE-2026-4482MEDIUM5.5The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windo...
CVE-2026-6010MEDIUM6.3A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknow...
CVE-2026-6007MEDIUM6.3A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the fi...
CVE-2026-6006MEDIUM6.3A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now