2026 CVE Vulnerabilities

53,405 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-24883MEDIUM5.5In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to ...
CVE-2026-24398MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restri...
CVE-2026-24116MEDIUM5.5Wasmtime is a runtime for WebAssembly. Starting in version 29.0.0 and prior to version 36.0.5, 40.0.3, and 41.0.1, on x8...
CVE-2026-23892MEDIUM5.9OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 a...
CVE-2026-22263MEDIUM5.3Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in htt...
CVE-2026-22261MEDIUM5.3Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handlin...
CVE-2026-0746MEDIUM6.4The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3....
CVE-2026-23881MEDIUM6.5Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 hav...
CVE-2026-0705MEDIUM6.7Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage...
CVE-2026-24868MEDIUM6.5Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.
CVE-2026-22796MEDIUM5.3Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_T...
CVE-2026-22795MEDIUM5.5Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. ...
CVE-2026-0648MEDIUM6.3The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_...
CVE-2026-1489MEDIUM5.4A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to me...
CVE-2026-1484MEDIUM4.2A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of inte...
CVE-2026-1213MEDIUM4.3All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modif...
CVE-2026-24829MEDIUM6.5Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: befor...
CVE-2026-24348MEDIUM6.1Multiple cross-site scripting vulnerabilities in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to execut...
CVE-2026-24347MEDIUM5.3Improper input validation in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to manipulate files in the /...
CVE-2026-1467MEDIUM5.3A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injec...
CVE-2026-24825MEDIUM6.9Missing Release of Memory after Effective Lifetime vulnerability in ydb-platform ydb (contrib/libs/yajl modules). This v...
CVE-2026-24824MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in yacy yacy_s...
CVE-2026-24820MEDIUM5.1Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated...
CVE-2026-24819MEDIUM6.3Improperly Controlled Sequential Memory Allocation vulnerability in foxinmy weixin4j (weixin4j-base/src/main/java/com/fo...
CVE-2026-24818MEDIUM6.9Out-of-bounds Read vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now