2026 CVE Vulnerabilities

51,426 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-21991MEDIUM5.5A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
CVE-2026-1629MEDIUM4.3Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel acces...
CVE-2026-32262MEDIUM4.3Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-R...
CVE-2026-30882MEDIUM6.1Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scrip...
CVE-2026-30876MEDIUM5.3Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with va...
CVE-2026-29516MEDIUM6.9Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability...
CVE-2026-26304MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, which ...
CVE-2026-29521MEDIUM5.1Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a cross-site request forgery vulnerability that allows atta...
CVE-2026-29520MEDIUM6.1Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a reflected cross-site scripting vulnerability in the Netwo...
CVE-2026-29513MEDIUM5.4Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows aut...
CVE-2026-29510MEDIUM5.4Hereta ETH-IMC408M firmware version 1.0.15 and prior contain a stored cross-site scripting vulnerability that allows aut...
CVE-2026-28490MEDIUM6.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic paddi...
CVE-2026-4270MEDIUM6.8Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= ...
CVE-2026-32587MEDIUM5.4Missing Authorization vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Exploiting Incorrectly Configured Access...
CVE-2026-32583MEDIUM5.3Missing Authorization vulnerability in Webnus Inc. Modern Events Calendar allows Exploiting Incorrectly Configured Acces...
CVE-2026-2455MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addres...
CVE-2026-24692MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in...
CVE-2026-21386MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when ...
CVE-2026-4265MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file p...
CVE-2026-4241MEDIUM6.3A vulnerability was identified in itsourcecode College Management System 1.0. The impacted element is an unknown functio...
CVE-2026-4238MEDIUM4.7A vulnerability has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing...
CVE-2026-4234MEDIUM6.3A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddControll...
CVE-2026-4233MEDIUM4.3A vulnerability was identified in ThingsGateway 12. This affects an unknown part of the file /api/file/download. The man...
CVE-2026-4230MEDIUM6.3A vulnerability has been found in vanna-ai vanna up to 2.0.2. Affected is the function update_sql of the file src/vanna/...
CVE-2026-4216MEDIUM5.3A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now