2026 CVE Vulnerabilities

64,840 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-55093MEDIUM6.1Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1...
CVE-2026-54559MEDIUM6.9PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c ...
CVE-2026-54247MEDIUM4.3Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes...
CVE-2026-54246MEDIUM5.7Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves clu...
CVE-2026-53717MEDIUM6.5Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway...
CVE-2026-18251MEDIUM4.3IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of...
CVE-2026-18065MEDIUM5.3IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information throu...
CVE-2026-17628MEDIUM5.4IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account d...
CVE-2026-17463MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could...
CVE-2026-17047MEDIUM5.4IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper req...
CVE-2026-16702MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could...
CVE-2026-16435MEDIUM5.9IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Int...
CVE-2026-16189MEDIUM4.8IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server...
CVE-2026-16188MEDIUM5.3IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server...
CVE-2026-16187MEDIUM6.5IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitiv...
CVE-2026-16186MEDIUM5.4IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.
CVE-2026-16185MEDIUM6.4IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console...
CVE-2026-16148MEDIUM4.6The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv...
CVE-2026-16147MEDIUM6.8The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on no...
CVE-2026-15924MEDIUM5.9Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of ...
CVE-2026-15887MEDIUM5.4IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requ...
CVE-2026-15634MEDIUM6.5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP requ...
CVE-2026-15412MEDIUM6.5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attack...
CVE-2026-15396MEDIUM6.5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP requ...
CVE-2026-90812MEDIUM4.3A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function chec...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now