2026 CVE Vulnerabilities

53,576 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-24047MEDIUM6.3Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functio...
CVE-2026-23990MEDIUM5.3The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterpr...
CVE-2026-23968MEDIUM5.5Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe...
CVE-2026-23630MEDIUM5.4Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code blo...
CVE-2026-23960MEDIUM5.4Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t...
CVE-2026-23516MEDIUM5.4CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0...
CVE-2026-23499MEDIUM5.4Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor...
CVE-2026-22849MEDIUM4.8Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor...
CVE-2026-22808MEDIUM5.4fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, i...
CVE-2026-23955MEDIUM4.2EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated ...
CVE-2026-20109MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE...
CVE-2026-20092MEDIUM6A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, l...
CVE-2026-20080MEDIUM5.3A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticat...
CVE-2026-20055MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE...
CVE-2026-1290MEDIUM5.3Authentication Bypass by Primary Weakness vulnerability in Jamf Jamf Pro allows unspecified impact.This issue affects Ja...
CVE-2026-22977MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv...
CVE-2026-0663MEDIUM4.9Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vau...
CVE-2026-22976MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix NULL deref when deactivatin...
CVE-2026-21985MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2026-21982MEDIUM6.4Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2026-21981MEDIUM4.6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2026-21980MEDIUM6.5Vulnerability in the Oracle Life Sciences Central Coding product of Oracle Health Sciences Applications (component: Plat...
CVE-2026-21979MEDIUM4.2Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th...
CVE-2026-21978MEDIUM6.5Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Rel...
CVE-2026-21975MEDIUM4.5Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.29 a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now