2026 CVE Vulnerabilities

44,056 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-44342MEDIUM5.3New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0...
CVE-2026-59828MEDIUM5.3Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions tha...
CVE-2026-58144MEDIUM5.4Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users wi...
CVE-2026-57054MEDIUM6.9A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS o...
CVE-2026-57031MEDIUM5.3An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper N...
CVE-2026-57029MEDIUM6A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series...
CVE-2026-57025MEDIUM6.8A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and...
CVE-2026-57024MEDIUM6.9A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos O...
CVE-2026-57021MEDIUM6.9An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows ...
CVE-2026-55605MEDIUM5.3DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hos...
CVE-2026-55424MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured ...
CVE-2026-55170MEDIUM5.4OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the dat...
CVE-2026-53962MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG s...
CVE-2026-53961MEDIUM6.5Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce...
CVE-2026-46413MEDIUM6.5Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users coul...
CVE-2026-45780MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer co...
CVE-2026-39245MEDIUM6.2decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file ...
CVE-2026-39243MEDIUM5.5decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and ...
CVE-2026-33803MEDIUM6.9An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve...
CVE-2026-33802MEDIUM6.8A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated...
CVE-2026-60120MEDIUM5.4Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows...
CVE-2026-33799MEDIUM5.3An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows...
CVE-2026-31267MEDIUM5.7Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. ...
CVE-2026-21901MEDIUM6.7A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolve...
CVE-2026-0277MEDIUM5.9An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a ma...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now