2026 CVE Vulnerabilities

57,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49256HIGH7.5Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and...
CVE-2026-46413MEDIUM6.5Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users coul...
CVE-2026-45788HIGH7.5Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads cou...
CVE-2026-45780MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer co...
CVE-2026-44787HIGH7.1Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow co...
CVE-2026-39246HIGH7.5decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (ty...
CVE-2026-39245MEDIUM6.2decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file ...
CVE-2026-39243MEDIUM5.5decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and ...
CVE-2026-38076HIGH7.5An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Deni...
CVE-2026-33803MEDIUM6.9An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve...
CVE-2026-33802MEDIUM6.8A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated...
CVE-2026-15276LOW3.3A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metad...
CVE-2026-15274LOW3.3A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v74...
CVE-2026-15271HIGH7.5A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 u...
CVE-2026-60120MEDIUM5.4Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows...
CVE-2026-55865HIGH7.1Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag with...
CVE-2026-55212HIGH7.1Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API class de...
CVE-2026-55208HIGH7.7Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated...
CVE-2026-55207HIGH8.8Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated atta...
CVE-2026-51926HIGH7.5An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php...
CVE-2026-51925HIGH8.1A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to exec...
CVE-2026-51924HIGH8.1An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and rep...
CVE-2026-51923HIGH8.1An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attac...
CVE-2026-33801HIGH7.1An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Ne...
CVE-2026-33800MEDIUM6.5An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now