2026 CVE Vulnerabilities

43,308 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-64211MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: srcu: Don't queue workqueue handlers to never-onlin...
CVE-2026-8308MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Softwa...
CVE-2026-7007MEDIUM4.6The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl....
CVE-2026-66007MEDIUM6.9Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder...
CVE-2026-66006MEDIUM6.9lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs...
CVE-2026-66005MEDIUM6.3Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that ...
CVE-2026-66004MEDIUM6BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all...
CVE-2026-55731MEDIUM6.6Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI...
CVE-2026-49326MEDIUM6.5Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest...
CVE-2026-17059MEDIUM6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloa...
CVE-2026-16802MEDIUM6.5Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear...
CVE-2026-16799MEDIUM5Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and ...
CVE-2026-16798MEDIUM6.5Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2....
CVE-2026-17048MEDIUM4.9A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs w...
CVE-2026-7484MEDIUM5.3External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Fu...
CVE-2026-66010MEDIUM6.1DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDL...
CVE-2026-66009MEDIUM6.3Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages...
CVE-2026-66008MEDIUM6.3Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target cla...
CVE-2026-46452MEDIUM5.3Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken dat...
CVE-2026-45812MEDIUM6.5Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event....
CVE-2026-16743MEDIUM5.5A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root ...
CVE-2026-16730MEDIUM5.5A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer set...
CVE-2026-15663MEDIUM4.9The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injecti...
CVE-2026-63317MEDIUM5.6Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected:...
CVE-2026-56391MEDIUM4.6GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--ch...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now