2026 CVE Vulnerabilities

60,215 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56410MEDIUM6.9xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56409MEDIUM6.5xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-56408MEDIUM6.9libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56407MEDIUM6.9libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56406MEDIUM6.9libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse...
CVE-2026-56405MEDIUM6.9libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56404MEDIUM6.9libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56403MEDIUM6.9libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56397CRITICAL9.6SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious...
CVE-2026-56396HIGH8.8phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that...
CVE-2026-56395CRITICAL9.6SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious...
CVE-2026-56394HIGH7.1Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the ex...
CVE-2026-56393MEDIUM4.8Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site ...
CVE-2026-56385MEDIUM5.3Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/pre...
CVE-2026-56384MEDIUM5.3Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user with...
CVE-2026-56383MEDIUM4.8Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the ...
CVE-2026-56382HIGH8.6Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability ...
CVE-2026-56381MEDIUM4.8Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where...
CVE-2026-56378HIGH8.2ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage...
CVE-2026-56367CRITICAL9.1ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding pat...
CVE-2026-56316MEDIUM6.9Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint t...
CVE-2026-56299MEDIUM6.9Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows...
CVE-2026-56265CRITICAL9.8Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the ...
CVE-2026-56253HIGH8.7Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that ...
CVE-2026-56251HIGH7Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now