2026 CVE Vulnerabilities

45,191 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12804MEDIUM4.3A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-p...
CVE-2026-56412MEDIUM5.9libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking ...
CVE-2026-56411MEDIUM6.9xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56410MEDIUM6.9xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56409MEDIUM6.5xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-56408MEDIUM6.9libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56407MEDIUM6.9libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56406MEDIUM6.9libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse...
CVE-2026-56405MEDIUM6.9libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56404MEDIUM6.9libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56403MEDIUM6.9libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56393MEDIUM4.8Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site ...
CVE-2026-56385MEDIUM5.3Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/pre...
CVE-2026-56384MEDIUM5.3Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user with...
CVE-2026-56383MEDIUM4.8Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the ...
CVE-2026-56381MEDIUM4.8Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where...
CVE-2026-56316MEDIUM6.9Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint t...
CVE-2026-56299MEDIUM6.9Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows...
CVE-2026-56236MEDIUM6.8Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations th...
CVE-2026-12799MEDIUM4.3A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_vi...
CVE-2026-12798MEDIUM6.3A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_open...
CVE-2026-12797MEDIUM6.3A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the...
CVE-2026-12796MEDIUM6.3A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_ope...
CVE-2026-12789MEDIUM4.7A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::exec...
CVE-2026-12788MEDIUM6.3A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerabi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now