2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-81920MEDIUM4.3Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The rese...
CVE-2026-81919MEDIUM4.3Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() ac...
CVE-2026-79409MEDIUM6.5An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and th...
CVE-2026-73467MEDIUM6.3On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal A...
CVE-2026-73466MEDIUM6.3On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to lo...
CVE-2026-73465MEDIUM6.3On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear tex...
CVE-2026-73451MEDIUM4.8On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Vi...
CVE-2026-69216MEDIUM5.4Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-siz...
CVE-2026-69214MEDIUM6.8Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a ...
CVE-2026-69212MEDIUM5.9Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware stri...
CVE-2026-69211MEDIUM4.8Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-inf...
CVE-2026-69201MEDIUM5.9Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode ...
CVE-2026-58773MEDIUM6.7In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This co...
CVE-2026-58767MEDIUM6.7In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. Th...
CVE-2026-58765MEDIUM6.7In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of p...
CVE-2026-58755MEDIUM6.7In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the cod...
CVE-2026-58751MEDIUM6.7In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could ...
CVE-2026-58747MEDIUM6.7In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could ...
CVE-2026-58739MEDIUM6.7In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. Th...
CVE-2026-58731MEDIUM6.2In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This ...
CVE-2026-58726MEDIUM6.7In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to l...
CVE-2026-58721MEDIUM4.4In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to lo...
CVE-2026-58718MEDIUM6.7In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation...
CVE-2026-58716MEDIUM6.7In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to loca...
CVE-2026-58698MEDIUM6.7In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now