2026 CVE Vulnerabilities

46,851 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-12015MEDIUM5.3Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the re...
CVE-2026-53818MEDIUM6.9OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-own...
CVE-2026-53809MEDIUM4.8OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using pr...
CVE-2026-53808MEDIUM6.5OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows a...
CVE-2026-53781MEDIUM5.3Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhausti...
CVE-2026-49949MEDIUM6CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercep...
CVE-2026-45802MEDIUM6FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template...
CVE-2026-53702MEDIUM6.5A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buf...
CVE-2026-53701MEDIUM6.5An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad....
CVE-2026-47250MEDIUM6.1mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the ...
CVE-2026-47177MEDIUM5.7Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use...
CVE-2026-47176MEDIUM5.7Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use...
CVE-2026-47173MEDIUM6.3Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor...
CVE-2026-47167MEDIUM5.3Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:s...
CVE-2026-47157MEDIUM6.5aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup ch...
CVE-2026-46698MEDIUM5.3Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unau...
CVE-2026-11986MEDIUM4.9A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabi...
CVE-2026-44489MEDIUM5.3Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created b...
CVE-2026-4096MEDIUM6.1IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th...
CVE-2026-3341MEDIUM5.4IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo...
CVE-2026-6338MEDIUM4.9A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13...
CVE-2026-53723MEDIUM5.8Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to descri...
CVE-2026-49214MEDIUM5.3guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII con...
CVE-2026-48998MEDIUM5.3guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host he...
CVE-2026-11956MEDIUM6.3A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now