2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-91961MEDIUM6.5FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails ...
CVE-2026-91960MEDIUM6.5FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allow...
CVE-2026-91959MEDIUM6.5FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway t...
CVE-2026-91958MEDIUM6.6FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbo...
CVE-2026-91956MEDIUM6.5FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function tha...
CVE-2026-91954MEDIUM6.5FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits...
CVE-2026-91953MEDIUM6.5FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fail...
CVE-2026-91952MEDIUM6.5FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding...
CVE-2026-91951MEDIUM6.5FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_curr...
CVE-2026-91950MEDIUM6.5FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsig...
CVE-2026-91946MEDIUM6.5FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU ...
CVE-2026-91945MEDIUM6.5FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to v...
CVE-2026-91944MEDIUM6.1crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the for...
CVE-2026-91942MEDIUM5.4crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns u...
CVE-2026-91936MEDIUM6.8Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_di...
CVE-2026-91849MEDIUM6.3A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /in...
CVE-2026-89307MEDIUM5.1The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject a...
CVE-2026-88620MEDIUM4.3SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/query...
CVE-2026-87793MEDIUM5.1The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica....
CVE-2026-59157MEDIUM6.5webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior ...
CVE-2026-58196MEDIUM4.7ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior ...
CVE-2026-55828MEDIUM6qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses stric...
CVE-2026-55776MEDIUM6.5OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with...
CVE-2026-55770MEDIUM6.8OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC...
CVE-2026-55701MEDIUM6.9The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now