2026 CVE Vulnerabilities

51,043 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-3114MEDIUM6.5Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompres...
CVE-2026-3113MEDIUM5.5Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on...
CVE-2026-3112MEDIUM4.9Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced ...
CVE-2026-34071MEDIUM6.1Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In version ...
CVE-2026-33470MEDIUM4.3Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, a low-...
CVE-2026-33469MEDIUM6.5Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an aut...
CVE-2026-33438MEDIUM6.5Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Versions st...
CVE-2026-33402MEDIUM6.1Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titl...
CVE-2026-33015MEDIUM5.2EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop ...
CVE-2026-33014MEDIUM5.2EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorizat...
CVE-2026-33009MEDIUM6.5EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memo...
CVE-2026-29905MEDIUM6.5Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (...
CVE-2026-29044MEDIUM6.5EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the...
CVE-2026-27814MEDIUM4.2EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race (C++ UB) triggered by an A 1-phas...
CVE-2026-27813MEDIUM5.3EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This i...
CVE-2026-26073MEDIUM5.9EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/...
CVE-2026-4897MEDIUM5.5A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to th...
CVE-2026-33397MEDIUM6.1The Angular SSR is a server-rise rendering tool for Angular applications. Versions on the 22.x branch prior to 22.0.0-ne...
CVE-2026-30162MEDIUM6.1Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.
CVE-2026-29976MEDIUM6.2Buffer Overflow vulnerability in ZerBea hcxpcapngtool v. 7.0.1-43-g2ee308e allows a local attacker to obtain sensitive i...
CVE-2026-29934MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to ...
CVE-2026-29933MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers ...
CVE-2026-26072MEDIUM4.2EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona...
CVE-2026-26071MEDIUM4.2EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurre...
CVE-2026-26070MEDIUM4.2EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now