2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-90786MEDIUM5.3A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the fil...
CVE-2026-90785MEDIUM5.3A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/comp...
CVE-2026-86349MEDIUM4.3Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting ...
CVE-2026-86348MEDIUM4.3Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenti...
CVE-2026-84179MEDIUM6.5Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and retu...
CVE-2026-82920MEDIUM5.5Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the...
CVE-2026-7208MEDIUM5.3Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows aut...
CVE-2026-73191MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is config...
CVE-2026-90957MEDIUM5.1Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains ...
CVE-2026-90955MEDIUM4.6Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user ac...
CVE-2026-90936MEDIUM4.3Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authent...
CVE-2026-90935MEDIUM4.3Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in ...
CVE-2026-90934MEDIUM4.3EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints t...
CVE-2026-90931MEDIUM5.4LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated...
CVE-2026-90930MEDIUM6.8File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reappl...
CVE-2026-90928MEDIUM6.5File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads e...
CVE-2026-90927MEDIUM6.5filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permission...
CVE-2026-90784MEDIUM5.3A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of ...
CVE-2026-90716MEDIUM5.5A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of t...
CVE-2026-90714MEDIUM6.3A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the f...
CVE-2026-78318MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. ...
CVE-2026-77883MEDIUM4.9Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate ...
CVE-2026-77147MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequa...
CVE-2026-75015MEDIUM4.9Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, ...
CVE-2026-90712MEDIUM4.3A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now