2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-71555MEDIUM4.1PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS do...
CVE-2026-71554MEDIUM5.3h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header ...
CVE-2026-71498MEDIUM5.1node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final byt...
CVE-2026-71497MEDIUM4.7jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectl...
CVE-2026-71478MEDIUM6.1league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the Attributes...
CVE-2026-71447MEDIUM6.9AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages...
CVE-2026-71446MEDIUM6.9AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedde...
CVE-2026-71439MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11....
CVE-2026-71437MEDIUM6.5Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11....
CVE-2026-71436MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10....
CVE-2026-71435MEDIUM6.1Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automag...
CVE-2026-71434MEDIUM5.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms...
CVE-2026-71433MEDIUM5.3LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoin...
CVE-2026-71430MEDIUM6.2node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function...
CVE-2026-71325MEDIUM4.8Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25...
CVE-2026-70639MEDIUM6.8llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper w...
CVE-2026-70631MEDIUM6.8FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in ...
CVE-2026-70630MEDIUM6.8FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na...
CVE-2026-70629MEDIUM6.8FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na...
CVE-2026-64677MEDIUM5.9Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not ...
CVE-2026-64664MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont...
CVE-2026-64663MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup...
CVE-2026-64662MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont...
CVE-2026-64654MEDIUM5.3GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed ex...
CVE-2026-64653MEDIUM5.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable pat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now