2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-48785MEDIUM4.8Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix...
CVE-2026-39040MEDIUM5.4BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (tru...
CVE-2026-39039MEDIUM5.3In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and se...
CVE-2026-39038MEDIUM6.1BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (tru...
CVE-2026-12910MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 1...
CVE-2026-12751MEDIUM5.4IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML cod...
CVE-2026-12750MEDIUM5.4IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authent...
CVE-2026-12749MEDIUM5.4IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authent...
CVE-2026-12742MEDIUM5.4IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted ...
CVE-2026-11927MEDIUM6.5IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party service...
CVE-2026-11918MEDIUM5.4IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mech...
CVE-2026-11864MEDIUM6.5IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0...
CVE-2026-91855MEDIUM5.3A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality o...
CVE-2026-91854MEDIUM4.3A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the fil...
CVE-2026-81897MEDIUM5.4In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not vali...
CVE-2026-81896MEDIUM5.4Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering ...
CVE-2026-81894MEDIUM5.4Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-im...
CVE-2026-79705MEDIUM4.5A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar arch...
CVE-2026-79699MEDIUM4.4A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. v...
CVE-2026-55863MEDIUM5.3motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w...
CVE-2026-54561MEDIUM6.2MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_i...
CVE-2026-54503MEDIUM4.3plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type...
CVE-2026-53658MEDIUM6.3Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP ...
CVE-2026-91992MEDIUM5.9Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused acr...
CVE-2026-91991MEDIUM5.4Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now