2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-91987MEDIUM6.5atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero...
CVE-2026-91986MEDIUM5.4gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attacke...
CVE-2026-91984MEDIUM4.3Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task'...
CVE-2026-91983MEDIUM4.3Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails t...
CVE-2026-91982MEDIUM4.3Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settin...
CVE-2026-91981MEDIUM4.3Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers...
CVE-2026-91980MEDIUM4.3vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enu...
CVE-2026-91979MEDIUM6.5Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial o...
CVE-2026-91971MEDIUM6.5Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing auth...
CVE-2026-91970MEDIUM6.5Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce a...
CVE-2026-91969MEDIUM6.5vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endp...
CVE-2026-91968MEDIUM6.5vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deepl...
CVE-2026-91967MEDIUM5AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL functi...
CVE-2026-91966MEDIUM5.8AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability...
CVE-2026-91963MEDIUM6.5FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirecti...
CVE-2026-91962MEDIUM6.3FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values fr...
CVE-2026-91961MEDIUM6.5FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails ...
CVE-2026-91960MEDIUM6.5FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allow...
CVE-2026-91959MEDIUM6.5FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway t...
CVE-2026-91958MEDIUM6.6FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbo...
CVE-2026-91956MEDIUM6.5FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function tha...
CVE-2026-91954MEDIUM6.5FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits...
CVE-2026-91953MEDIUM6.5FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fail...
CVE-2026-91952MEDIUM6.5FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding...
CVE-2026-91951MEDIUM6.5FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_curr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now