2026 CVE Vulnerabilities

48,018 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-43979MEDIUM5Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdo...
CVE-2026-46561MEDIUM5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based p...
CVE-2026-45307MEDIUM6.1Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the...
CVE-2026-45306MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509...
CVE-2026-45297MEDIUM5.3OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assi...
CVE-2026-45021MEDIUM5.1Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2...
CVE-2026-44796MEDIUM6.5Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bul...
CVE-2026-44794MEDIUM5.4Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-o...
CVE-2026-9091MEDIUM5.3Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass c...
CVE-2026-47676MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() stri...
CVE-2026-47675MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() ...
CVE-2026-47674MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restricti...
CVE-2026-47673MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk ...
CVE-2026-45292MEDIUM5.3opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing tel...
CVE-2026-45078MEDIUM5.5Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synaps...
CVE-2026-41185MEDIUM6.5When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to at...
CVE-2026-41184MEDIUM6.5In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration...
CVE-2026-41160MEDIUM4.3EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Ac...
CVE-2026-41141MEDIUM6.5EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:...
CVE-2026-48735MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can cr...
CVE-2026-48525MEDIUM5.3PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the u...
CVE-2026-48523MEDIUM5.4PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list ...
CVE-2026-48522MEDIUM4.2PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to url...
CVE-2026-48155MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr...
CVE-2026-47762MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now