2026 CVE Vulnerabilities

50,629 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-35599MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function use...
CVE-2026-35598MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesB...
CVE-2026-35596MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a...
CVE-2026-22560MEDIUM5.3An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by...
CVE-2026-40227MEDIUM5.5In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that...
CVE-2026-40226MEDIUM6.4In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
CVE-2026-40225MEDIUM6.4In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel outp...
CVE-2026-40223MEDIUM5.5In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exi...
CVE-2026-40023MEDIUM5.3Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions...
CVE-2026-40021MEDIUM5.3Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLa...
CVE-2026-35594MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (Get...
CVE-2026-34477MEDIUM5.9The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna...
CVE-2026-29043MEDIUM5.5HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can t...
CVE-2026-31262MEDIUM6.1Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtai...
CVE-2026-6067MEDIUM5.5A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_...
CVE-2026-5774MEDIUM6.4Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow a...
CVE-2026-5412MEDIUM6.5In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated us...
CVE-2026-31412MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: Fix potential integer ...
CVE-2026-6042MEDIUM4.8A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/icon...
CVE-2026-33457MEDIUM6.3Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated ...
CVE-2026-33455MEDIUM6.3Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livest...
CVE-2026-6035MEDIUM4.3A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unkno...
CVE-2026-6034MEDIUM4.3A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the fi...
CVE-2026-6033MEDIUM6.3A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedet...
CVE-2026-6032MEDIUM4.3A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /chec...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now