2026 CVE Vulnerabilities

48,557 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-42841MEDIUM4.8Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject...
CVE-2026-42612MEDIUM5.4Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/g...
CVE-2026-42610MEDIUM6.5Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.upda...
CVE-2026-3320MEDIUM5.1Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input ...
CVE-2026-3319MEDIUM5.1Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input ...
CVE-2026-31246MEDIUM6.5GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (...
CVE-2026-8290MEDIUM6.5A security flaw has been discovered in Open5GS up to 2.7.7. This issue affects the function smf_nsmf_handle_update_data_...
CVE-2026-8289MEDIUM6.5A vulnerability was identified in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_update_da...
CVE-2026-8288MEDIUM6.5A vulnerability was determined in Open5GS up to 2.7.7. This affects the function gsm_handle_pdu_session_modification_qos...
CVE-2026-6956MEDIUM5.1ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL ...
CVE-2026-6909MEDIUM5.1ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL ...
CVE-2026-26946MEDIUM6.7Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege...
CVE-2026-43826MEDIUM6.5The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:pa...
CVE-2026-41018MEDIUM6.5The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user...
CVE-2026-5084MEDIUM6.5WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely. The session handler generates t...
CVE-2026-1677MEDIUM5.3Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enable...
CVE-2026-8274MEDIUM5.3A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of th...
CVE-2026-8270MEDIUM6.5A vulnerability was determined in Open5GS up to 2.7.7. The affected element is the function ogs_nas_parse_qos_rules of t...
CVE-2026-8269MEDIUM6.5A vulnerability was found in Open5GS up to 2.7.7. Impacted is the function smf_nsmf_handle_create_sm_context of the comp...
CVE-2026-8268MEDIUM6.5A vulnerability has been found in Open5GS up to 2.7.7. This issue affects the function OpenAPI_list_create of the compon...
CVE-2026-8267MEDIUM6.5A flaw has been found in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_created_data_in_vs...
CVE-2026-8266MEDIUM6.5A vulnerability was detected in Open5GS up to 2.7.7. This affects the function gsm_build_pdu_session_establishment_accep...
CVE-2026-8261MEDIUM5.9A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirr...
CVE-2026-8258MEDIUM5.3A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstrin...
CVE-2026-8257MEDIUM5.5A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now