2026 CVE Vulnerabilities

47,686 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-48587MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan...
CVE-2026-47325MEDIUM6.9ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's password...
CVE-2026-47324MEDIUM5.1ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes o...
CVE-2026-44546MEDIUM5.3daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket...
CVE-2026-10722MEDIUM5.5A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go...
CVE-2026-5078MEDIUM5.3Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization reque...
CVE-2026-10703MEDIUM6.3A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRo...
CVE-2026-10693MEDIUM6.3A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulner...
CVE-2026-9732MEDIUM4.3The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2026-7421MEDIUM4.4The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...
CVE-2026-10692MEDIUM4.3A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_patte...
CVE-2026-10691MEDIUM4.3A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function o...
CVE-2026-10690MEDIUM6.3A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of ...
CVE-2026-44653MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users...
CVE-2026-42507MEDIUM5.3When returning errors, functions in the net/textproto package would include its input as part of the error. This might a...
CVE-2026-41412MEDIUM4.9alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio...
CVE-2026-27145MEDIUM6.5(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN...
CVE-2026-10718MEDIUM4.6Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms...
CVE-2026-10688MEDIUM5.5A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted elem...
CVE-2026-10662MEDIUM6.3A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element i...
CVE-2026-35212MEDIUM6.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7...
CVE-2026-10661MEDIUM4.3A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the f...
CVE-2026-10650MEDIUM5.5A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of t...
CVE-2026-45289MEDIUM5.3CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526...
CVE-2026-41569MEDIUM6.1authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now