2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-92077MEDIUM6.5Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156,...
CVE-2026-92070MEDIUM4.3Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thun...
CVE-2026-92069MEDIUM5.4Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunder...
CVE-2026-92068MEDIUM5.4Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thund...
CVE-2026-92063MEDIUM6.5Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92039MEDIUM6.3Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, T...
CVE-2026-92031MEDIUM6.5Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140...
CVE-2026-92030MEDIUM5.4Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firef...
CVE-2026-92005MEDIUM5.3Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16...
CVE-2026-15609MEDIUM6.4The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2026-92003MEDIUM6.9Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API auth...
CVE-2026-92002MEDIUM5.1Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid exce...
CVE-2026-91997MEDIUM5.3evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always eval...
CVE-2026-91994MEDIUM6.5Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddlewa...
CVE-2026-91993MEDIUM4.3Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoin...
CVE-2026-91922MEDIUM6.1Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/pa...
CVE-2026-91786MEDIUM6.1A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to vali...
CVE-2026-86818MEDIUM4.8fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parse...
CVE-2026-86472MEDIUM4.8fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3...
CVE-2026-80489MEDIUM5.9Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the G...
CVE-2026-77117MEDIUM5.9Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the...
CVE-2026-52828MEDIUM5.3Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportC...
CVE-2026-52826MEDIUM5.3Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/...
CVE-2026-52825MEDIUM5.3Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/...
CVE-2026-52823MEDIUM5.3Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now