2026 CVE Vulnerabilities

48,557 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-42314MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are s...
CVE-2026-42312MEDIUM6.8pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API...
CVE-2026-41257MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in...
CVE-2026-41256MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncate...
CVE-2026-41250MEDIUM5.7Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stor...
CVE-2026-40612MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth...
CVE-2026-3048MEDIUM5.1An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3...
CVE-2026-38569MEDIUM5.4HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fi...
CVE-2026-34095MEDIUM6.1Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/...
CVE-2026-34093MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne...
CVE-2026-44737MEDIUM6.2grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Gra...
CVE-2026-42842MEDIUM5.4The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) v...
CVE-2026-36906MEDIUM6.1Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log ...
CVE-2026-31252MEDIUM5.7CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera...
CVE-2026-8292MEDIUM6.5A security vulnerability has been detected in Open5GS up to 2.7.7. The affected element is the function yuarel_parse in ...
CVE-2026-8291MEDIUM6.5A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogs_nnrf_nfm_handle_nf_profile of the fi...
CVE-2026-7820MEDIUM6.9Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS o...
CVE-2026-7814MEDIUM4.8Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controll...
CVE-2026-6815MEDIUM5.9An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path s...
CVE-2026-6093MEDIUM6Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose record...
CVE-2026-44201MEDIUM5.3Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and I...
CVE-2026-44200MEDIUM6.5Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim...
CVE-2026-44199MEDIUM6.5Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim...
CVE-2026-44198MEDIUM4.3Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without ...
CVE-2026-44197MEDIUM6.5Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now