2026 CVE Vulnerabilities

53,410 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-23888MEDIUM6.5pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows mali...
CVE-2026-1445MEDIUM4.7A vulnerability was found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This vulnerability...
CVE-2026-24439MEDIUM6.5Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Option...
CVE-2026-24437MEDIUM5.5Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content wi...
CVE-2026-24435MEDIUM6.5Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resour...
CVE-2026-24433MEDIUM5.4Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vul...
CVE-2026-24432MEDIUM4.3Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) pr...
CVE-2026-24431MEDIUM6.5Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in ...
CVE-2026-1446MEDIUM5There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop appli...
CVE-2026-1224MEDIUM6.5Tanium addressed an uncontrolled resource consumption vulnerability in Discover.
CVE-2026-0925MEDIUM4.9Tanium addressed an improper input validation vulnerability in Discover.
CVE-2026-1429MEDIUM5.4Single Sign-On Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authen...
CVE-2026-1425MEDIUM6.3A security flaw has been discovered in pymumu SmartDNS up to 47.1. This vulnerability affects the function _dns_decode_r...
CVE-2026-1421MEDIUM5.4A vulnerability has been found in code-projects Online Examination System 1.0. Affected is an unknown function of the co...
CVE-2026-1411MEDIUM6.1A flaw has been found in Beetel 777VR1 up to 01.00.09/01.00.09_55. The affected element is an unknown function of the co...
CVE-2026-1410MEDIUM6.4A vulnerability was detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. Impacted is an unknown function of the compone...
CVE-2026-1409MEDIUM4.2A security vulnerability has been detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. This issue affects some unknown ...
CVE-2026-1408MEDIUM4.2A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of t...
CVE-2026-1407MEDIUM4.2A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01.00.09_55. This affects an unknown part of the com...
CVE-2026-23011MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to...
CVE-2026-23009MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xhci: sideband: don't dereference freed ring when r...
CVE-2026-23008MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix KMS with 3D on HW version 10 HW ve...
CVE-2026-23007MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: block: zero non-PI portion of auto integrity buffer...
CVE-2026-23006MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: tlv320adcx140: fix null pointer The "snd_soc...
CVE-2026-23005MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state wh...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now