2026 CVE Vulnerabilities

43,808 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-47703MEDIUM5.3AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggere...
CVE-2026-20146MEDIUM5.5A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a...
CVE-2026-1563MEDIUM4.8Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a u...
CVE-2026-1562MEDIUM4.8Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user...
CVE-2026-9007MEDIUM5.5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL...
CVE-2026-62843MEDIUM6.8File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-47160MEDIUM5.8Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png en...
CVE-2026-47159MEDIUM6.9Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-valid...
CVE-2026-45150MEDIUM6.3Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security no...
CVE-2026-41580MEDIUM6.1Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirl...
CVE-2026-62294MEDIUM5.1Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to...
CVE-2026-61646MEDIUM6.3FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only ...
CVE-2026-60065MEDIUM5.3When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filte...
CVE-2026-60062MEDIUM6.4The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files ou...
CVE-2026-54562MEDIUM6.5Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow acc...
CVE-2026-33213MEDIUM6.1Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's a...
CVE-2026-59838MEDIUM4.8A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4....
CVE-2026-58559MEDIUM6.5DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availabilit...
CVE-2026-58557MEDIUM4.8Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availab...
CVE-2026-58556MEDIUM5.1Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affe...
CVE-2026-58555MEDIUM6.6Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect ava...
CVE-2026-58554MEDIUM6.6Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-58553MEDIUM4Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af...
CVE-2026-58552MEDIUM5.1Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af...
CVE-2026-58551MEDIUM5.1Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now