2026 CVE Vulnerabilities

64,840 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-90810MEDIUM6.3A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function...
CVE-2026-90808MEDIUM6.3A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._...
CVE-2026-89021MEDIUM6.9MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extractio...
CVE-2026-89020MEDIUM4.3MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in ...
CVE-2026-82519MEDIUM4.3Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allow...
CVE-2026-19543MEDIUM6.2IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input valid...
CVE-2026-18515MEDIUM4.3IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Naviga...
CVE-2026-18151MEDIUM4.2IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race c...
CVE-2026-15893MEDIUM6.5net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reach...
CVE-2026-91081MEDIUM5.8Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous...
CVE-2026-91021MEDIUM5.4Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share ren...
CVE-2026-90807MEDIUM6.3A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the...
CVE-2026-90806MEDIUM6.3A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCase...
CVE-2026-57581MEDIUM5.3DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applic...
CVE-2026-57570MEDIUM6.5backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha...
CVE-2026-55847MEDIUM6.1Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js ...
CVE-2026-55846MEDIUM6.2Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP ser...
CVE-2026-55832MEDIUM6.1Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2...
CVE-2026-54723MEDIUM6.5devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a ...
CVE-2026-54181MEDIUM5.4backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha...
CVE-2026-54177MEDIUM6.6backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha...
CVE-2026-54176MEDIUM6.5backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha...
CVE-2026-54150MEDIUM6.9next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-vide...
CVE-2026-53495MEDIUM6.8containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the ...
CVE-2026-50157MEDIUM6.5Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorize...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now