2026 CVE Vulnerabilities

51,359 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-26004MEDIUM6.5Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organi...
CVE-2026-25937MEDIUM6.5GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malic...
CVE-2026-20643MEDIUM5.4A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Backgrou...
CVE-2026-1264MEDIUM6.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2026-4349MEDIUM6.3A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the...
CVE-2026-32840MEDIUM5.4Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_na...
CVE-2026-32839MEDIUM6.5Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remot...
CVE-2026-32838MEDIUM5.9Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implemen...
CVE-2026-1267MEDIUM6.5IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and a...
CVE-2026-2809MEDIUM6.7Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe...
CVE-2026-3563MEDIUM5.5Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an auth...
CVE-2026-32837MEDIUM5.1miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerabi...
CVE-2026-32836MEDIUM6.9dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled me...
CVE-2026-32293MEDIUM6.3The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL...
CVE-2026-4147MEDIUM4.3An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is...
CVE-2026-28506MEDIUM4.3Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for...
CVE-2026-4324MEDIUM5.4A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of use...
CVE-2026-28563MEDIUM4.3Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filt...
CVE-2026-26929MEDIUM6.5Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filterin...
CVE-2026-3634MEDIUM6.5A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage...
CVE-2026-3633MEDIUM6.5A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function...
CVE-2026-3632MEDIUM5.5A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because ...
CVE-2026-23241MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at"...
CVE-2026-4202MEDIUM4.3The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of ...
CVE-2026-32586MEDIUM5.3Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now