2026 CVE Vulnerabilities

44,067 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-39243MEDIUM5.5decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and ...
CVE-2026-33803MEDIUM6.9An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve...
CVE-2026-33802MEDIUM6.8A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated...
CVE-2026-60120MEDIUM5.4Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows...
CVE-2026-33799MEDIUM5.3An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows...
CVE-2026-31267MEDIUM5.7Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. ...
CVE-2026-21901MEDIUM6.7A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolve...
CVE-2026-0277MEDIUM5.9An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a ma...
CVE-2026-0275MEDIUM6.7A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administ...
CVE-2026-59149MEDIUM6.5Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is ...
CVE-2026-58198MEDIUM5.5ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrai...
CVE-2026-55590MEDIUM6.1CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior ...
CVE-2026-54695MEDIUM6.5Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1...
CVE-2026-54004MEDIUM6.3Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enab...
CVE-2026-50188MEDIUM6.9Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Htt...
CVE-2026-49274MEDIUM5.3Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with role...
CVE-2026-0285MEDIUM4.9A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated admini...
CVE-2026-0282MEDIUM6.5A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network ac...
CVE-2026-0279MEDIUM6.1Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, Global...
CVE-2026-61344MEDIUM6.9The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that ...
CVE-2026-59817MEDIUM5.3Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed a...
CVE-2026-43752MEDIUM4.9An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicio...
CVE-2026-15204MEDIUM5.5A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerab...
CVE-2026-15202MEDIUM4.3A security vulnerability has been detected in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp/yzm...
CVE-2026-15195MEDIUM6.3A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Po...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now