2026 CVE Vulnerabilities

51,340 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27978MEDIUM4.3Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-27977MEDIUM5.4Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-27448MEDIUM5.3pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a u...
CVE-2026-26004MEDIUM6.5Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organi...
CVE-2026-25937MEDIUM6.5GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malic...
CVE-2026-20643MEDIUM5.4A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Backgrou...
CVE-2026-1264MEDIUM6.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2026-4349MEDIUM6.3A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the...
CVE-2026-32840MEDIUM5.4Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_na...
CVE-2026-32839MEDIUM6.5Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remot...
CVE-2026-32838MEDIUM5.9Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implemen...
CVE-2026-1267MEDIUM6.5IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and a...
CVE-2026-2809MEDIUM6.7Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe...
CVE-2026-3563MEDIUM5.5Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an auth...
CVE-2026-32837MEDIUM5.1miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerabi...
CVE-2026-32836MEDIUM6.9dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled me...
CVE-2026-32293MEDIUM6.3The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL...
CVE-2026-4147MEDIUM4.3An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is...
CVE-2026-28506MEDIUM4.3Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for...
CVE-2026-4324MEDIUM5.4A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of use...
CVE-2026-28563MEDIUM4.3Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filt...
CVE-2026-26929MEDIUM6.5Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filterin...
CVE-2026-3634MEDIUM6.5A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage...
CVE-2026-3633MEDIUM6.5A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function...
CVE-2026-3632MEDIUM5.5A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now