2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-61632MEDIUM5.3PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.2...
CVE-2026-5336MEDIUM6.8The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren...
CVE-2026-54717MEDIUM5.4Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable...
CVE-2026-50159MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 ...
CVE-2026-49391MEDIUM5.1Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported co...
CVE-2026-48083MEDIUM6.5OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48078MEDIUM5.3OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48077MEDIUM5.3OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48076MEDIUM6.5OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-clie...
CVE-2026-48075MEDIUM6.5OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48071MEDIUM5.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-47185MEDIUM5.1Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspac...
CVE-2026-45573MEDIUM6.4Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45572MEDIUM4.8Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45415MEDIUM6Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-43630MEDIUM6.5llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p...
CVE-2026-41861MEDIUM4.2Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with ...
CVE-2026-19146MEDIUM5.3Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromis...
CVE-2026-19127MEDIUM6.5An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflo...
CVE-2026-19108MEDIUM5.3A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetVa...
CVE-2026-19071MEDIUM6.3A flaw has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewa...
CVE-2026-19070MEDIUM6.3A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the fil...
CVE-2026-19069MEDIUM6.3A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This affects an unknown funct...
CVE-2026-19068MEDIUM6.3A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi...
CVE-2026-19067MEDIUM6.3A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now