2026 CVE Vulnerabilities

43,311 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-64795MEDIUM5.4Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provide...
CVE-2026-64794MEDIUM6.5Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - ...
CVE-2026-63281MEDIUM4.8Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values coul...
CVE-2026-13074MEDIUM6.9An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combinati...
CVE-2026-13073MEDIUM5.3An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte...
CVE-2026-13070MEDIUM6A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons...
CVE-2026-13068MEDIUM4.3An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate ac...
CVE-2026-13063MEDIUM5.3An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem...
CVE-2026-13061MEDIUM5.3An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi...
CVE-2026-13058MEDIUM6.5An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf...
CVE-2026-13057MEDIUM6.5An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In...
CVE-2026-3482MEDIUM5.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6....
CVE-2026-65650MEDIUM4.3Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
CVE-2026-7328MEDIUM6.8Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CM...
CVE-2026-65012MEDIUM6.3InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_fo...
CVE-2026-65011MEDIUM5.3Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de...
CVE-2026-16615MEDIUM6.8A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, ...
CVE-2026-64828MEDIUM6.1Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attac...
CVE-2026-44276MEDIUM4.4Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauth...
CVE-2026-10822MEDIUM6.5If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequ...
CVE-2026-10723MEDIUM6.8BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMA...
CVE-2026-56444MEDIUM5.9In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve...
CVE-2026-56416MEDIUM4.8In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSI...
CVE-2026-55991MEDIUM5.9In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 asserti...
CVE-2026-55990MEDIUM5.9In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:'...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now