2026 CVE Vulnerabilities

48,557 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-45025MEDIUM6.8WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln...
CVE-2026-42887MEDIUM4.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulne...
CVE-2026-42886MEDIUM4.9Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint dec...
CVE-2026-42885MEDIUM4.3Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpo...
CVE-2026-42884MEDIUM4.3Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/col...
CVE-2026-42883MEDIUM6.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpo...
CVE-2026-42876MEDIUM4.9External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-42875MEDIUM5.3External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-42872MEDIUM6.1WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) v...
CVE-2026-42870MEDIUM6.4WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw...
CVE-2026-42565MEDIUM4.3@workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirec...
CVE-2026-42050MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9...
CVE-2026-8318MEDIUM5.5A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by t...
CVE-2026-45222MEDIUM6.9Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with def...
CVE-2026-43968MEDIUM4Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splittin...
CVE-2026-42871MEDIUM6.9WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displa...
CVE-2026-42866MEDIUM6.7Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write...
CVE-2026-7308MEDIUM5.1An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript t...
CVE-2026-4893MEDIUM5.3An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS pac...
CVE-2026-4891MEDIUM5.3A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a den...
CVE-2026-45005MEDIUM6OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to re...
CVE-2026-45003MEDIUM5OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC...
CVE-2026-45002MEDIUM6.3OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks...
CVE-2026-45000MEDIUM5OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skip...
CVE-2026-44999MEDIUM6.3OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webho...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now