2026 CVE Vulnerabilities

61,018 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12804MEDIUM4.3A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-p...
CVE-2026-56412MEDIUM5.9libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking ...
CVE-2026-56411MEDIUM6.9xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56410MEDIUM6.9xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56409MEDIUM6.5xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-56408MEDIUM6.9libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56407MEDIUM6.9libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56406MEDIUM6.9libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse...
CVE-2026-56405MEDIUM6.9libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56404MEDIUM6.9libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56403MEDIUM6.9libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56397CRITICAL9.6SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious...
CVE-2026-56396HIGH8.8phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that...
CVE-2026-56395Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.
CVE-2026-56394HIGH7.1Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the ex...
CVE-2026-56393MEDIUM4.8Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site ...
CVE-2026-56385MEDIUM5.3Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/pre...
CVE-2026-56384MEDIUM5.3Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user with...
CVE-2026-56383MEDIUM4.8Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the ...
CVE-2026-56382HIGH8.6Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability ...
CVE-2026-56381MEDIUM4.8Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where...
CVE-2026-56378HIGH8.2ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage...
CVE-2026-56367CRITICAL9.1ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding pat...
CVE-2026-56316MEDIUM6.9Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint t...
CVE-2026-56299MEDIUM6.9Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now