2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-90793MEDIUM5.4A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/...
CVE-2026-90792MEDIUM4.3A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegr...
CVE-2026-90463MEDIUM4A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending spec...
CVE-2026-88819MEDIUM6.3In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.
CVE-2026-55795MEDIUM6.9Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controll...
CVE-2026-55236MEDIUM5.9langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-cre...
CVE-2026-55235MEDIUM5.9langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a r...
CVE-2026-54529MEDIUM5.3SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.p...
CVE-2026-53708MEDIUM6.6ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for M...
CVE-2026-4103MEDIUM6.4Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered w...
CVE-2026-90791MEDIUM6.3A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the f...
CVE-2026-90790MEDIUM6.3A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_not...
CVE-2026-82437MEDIUM4.3Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For ...
CVE-2026-82434MEDIUM6.5Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payl...
CVE-2026-82433MEDIUM6.5Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level author...
CVE-2026-82426MEDIUM6.5Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a serv...
CVE-2026-82019MEDIUM4.2TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows u...
CVE-2026-57128MEDIUM4.3PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praison...
CVE-2026-57120MEDIUM6.5PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime asse...
CVE-2026-57115MEDIUM6.5PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the ini...
CVE-2026-12985MEDIUM6.8Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Re...
CVE-2026-90941MEDIUM4.3novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that all...
CVE-2026-90940MEDIUM5.3novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endp...
CVE-2026-90939MEDIUM6.5novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks prop...
CVE-2026-90788MEDIUM4.7A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now