2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-59823MEDIUM5.3LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated ...
CVE-2026-92605MEDIUM6.5IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, a...
CVE-2026-92416MEDIUM4.3A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_repo...
CVE-2026-92413MEDIUM4.3A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is...
CVE-2026-88593MEDIUM6.1kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes ...
CVE-2026-84397MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2026-69147MEDIUM6.5vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions ...
CVE-2026-18120MEDIUM5.9Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invokin...
CVE-2026-92603MEDIUM6.5ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that...
CVE-2026-92601MEDIUM6.5Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission def...
CVE-2026-92600MEDIUM6.5Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysU...
CVE-2026-92402MEDIUM6.3A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affect...
CVE-2026-87028MEDIUM6.5Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint bel...
CVE-2026-85732MEDIUM4.7oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go a...
CVE-2026-85386MEDIUM6.1Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload quest...
CVE-2026-84993MEDIUM6.5MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 a...
CVE-2026-71182MEDIUM6Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Lin...
CVE-2026-71181MEDIUM6Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Lin...
CVE-2026-59944MEDIUM6.1Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or...
CVE-2026-57173MEDIUM6.5vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v...
CVE-2026-92627MEDIUM4.6A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a ...
CVE-2026-92615MEDIUM6.6A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-reposito...
CVE-2026-76104MEDIUM5.5Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerabi...
CVE-2026-26947MEDIUM6.7Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privileg...
CVE-2026-19607MEDIUM5.3A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now