2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-92842MEDIUM5.9The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a l...
CVE-2026-91768MEDIUM6.5The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen...
CVE-2026-63432MEDIUM6.5Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/...
CVE-2026-63431MEDIUM6.5Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently autho...
CVE-2026-100502MEDIUM5Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attacker...
CVE-2026-100501MEDIUM6.5Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api...
CVE-2026-100418MEDIUM5.3Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that ...
CVE-2026-100383MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-100381MEDIUM5.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-96879MEDIUM6.9Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki -...
CVE-2026-91769MEDIUM4.3PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matc...
CVE-2026-91767MEDIUM6.5php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS...
CVE-2026-91766MEDIUM5.9When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authori...
CVE-2026-6103MEDIUM4.3phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 oc...
CVE-2026-17545MEDIUM6.9On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM...
CVE-2026-100388MEDIUM5.4RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages i...
CVE-2026-100380MEDIUM5.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-100379MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App a...
CVE-2026-100378MEDIUM5.3Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionali...
CVE-2026-100377MEDIUM6.9Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda ...
CVE-2026-100376MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-96878MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ...
CVE-2026-96877MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ...
CVE-2026-96876MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ...
CVE-2026-96875MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now