2026 CVE Vulnerabilities

51,444 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-32777MEDIUM5.5libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CVE-2026-32776MEDIUM5.5libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVE-2026-32774MEDIUM5.4Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers...
CVE-2026-32772MEDIUM4.7telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON ...
CVE-2026-32724MEDIUM5.3PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the Mav...
CVE-2026-32719MEDIUM6.4AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-32713MEDIUM6.5PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink F...
CVE-2026-32709MEDIUM6.8PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerabil...
CVE-2026-32707MEDIUM6.1PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in it...
CVE-2026-32705MEDIUM6.8PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string term...
CVE-2026-32704MEDIUM6.5SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminR...
CVE-2026-32702MEDIUM5.3Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c...
CVE-2026-32630MEDIUM5.3file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excess...
CVE-2026-2578MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which all...
CVE-2026-2491MEDIUM6.3Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to...
CVE-2026-2476MEDIUM4.3Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with...
CVE-2026-2463MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user perm...
CVE-2026-2462MEDIUM6.6Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI t...
CVE-2026-2461MEDIUM4.3Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modi...
CVE-2026-2458MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership wh...
CVE-2026-2457MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metada...
CVE-2026-2456MEDIUM5.7Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of respon...
CVE-2026-2233MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-26246MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process...
CVE-2026-25783MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now