2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10128MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbit...
CVE-2026-7646MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other u...
CVE-2026-70607MEDIUM5.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-20311MEDIUM6.3A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta...
CVE-2026-20308MEDIUM4.3A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta...
CVE-2026-20294MEDIUM6.5A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, rem...
CVE-2026-20289MEDIUM5.7A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privilege...
CVE-2026-20288MEDIUM6.5A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nb...
CVE-2026-20198MEDIUM4.8A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an aut...
CVE-2026-20028MEDIUM5A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker...
CVE-2026-18927MEDIUM6.3A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d4...
CVE-2026-14587MEDIUM5.5Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask...
CVE-2026-70606MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6...
CVE-2026-70605MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70603MEDIUM6Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6,...
CVE-2026-70602MEDIUM6.6Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70599MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,...
CVE-2026-70597MEDIUM6.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70596MEDIUM4.3Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user ...
CVE-2026-70595MEDIUM4Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, s...
CVE-2026-53992MEDIUM6.1ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remot...
CVE-2026-50749MEDIUM6.5Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica...
CVE-2026-49331MEDIUM6.5A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for...
CVE-2026-48912MEDIUM6.5Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ...
CVE-2026-39924MEDIUM6.8Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now