2026 CVE Vulnerabilities

53,401 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-1665MEDIUM5.4A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() fun...
CVE-2026-24904MEDIUM5.3TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, ...
CVE-2026-24846MEDIUM5malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 1.8...
CVE-2026-24845MEDIUM6.5malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.1...
CVE-2026-1623MEDIUM6.3A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the function setUpgradeFW of the file /cgi-bin...
CVE-2026-25068MEDIUM4.6alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in t...
CVE-2026-24687MEDIUM6.5Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authent...
CVE-2026-1601MEDIUM6.3A weakness has been identified in Totolink A7000R 4.1cu.4154. The impacted element is the function setUploadUserData of ...
CVE-2026-24414MEDIUM5.5The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of W...
CVE-2026-24413MEDIUM5.5Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15....
CVE-2026-1600MEDIUM4.3A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted ele...
CVE-2026-1599MEDIUM4.3A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected ele...
CVE-2026-1598MEDIUM5.4A vulnerability was found in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. Impacted is an unknow...
CVE-2026-0936MEDIUM5.1An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused ...
CVE-2026-1469MEDIUM5.4Stored Cross-Site Scripting (XSS) in RLE NOVA's PlanManager. This vulnerability allows an attacker to execute JavaScript...
CVE-2026-22764MEDIUM6.5Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low pri...
CVE-2026-23571MEDIUM6.8A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-Run...
CVE-2026-23570MEDIUM6.5A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution S...
CVE-2026-23567MEDIUM6.5An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution S...
CVE-2026-23566MEDIUM6.5A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi...
CVE-2026-23565MEDIUM6.5A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi...
CVE-2026-23564MEDIUM6.5A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi...
CVE-2026-25067MEDIUM5.3SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the bac...
CVE-2026-1549MEDIUM4.3A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionalit...
CVE-2026-24889MEDIUM5.3soroban-sdk is a Rust SDK for Soroban contracts. Arithmetic overflow can be triggered in the `Bytes::slice`, `Vec::slice...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now