2026 CVE Vulnerabilities

48,561 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-45181MEDIUM6.5Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), whi...
CVE-2026-8210MEDIUM5.3A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Linux/macOS. Affected by this vulnerabilit...
CVE-2026-8195MEDIUM4.3A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-mod...
CVE-2026-8194MEDIUM4.3A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include...
CVE-2026-42576MEDIUM6.5apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKey...
CVE-2026-42333MEDIUM6.3Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to ve...
CVE-2026-42258MEDIUM5.3Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5...
CVE-2026-42256MEDIUM6.5Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before...
CVE-2026-8193MEDIUM6.3A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf...
CVE-2026-8198MEDIUM5.3The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to A...
CVE-2026-8185MEDIUM6.3A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of t...
CVE-2026-32683MEDIUM5.3Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transm...
CVE-2026-1749MEDIUM6.8There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated u...
CVE-2026-42310MEDIUM5.5Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF ...
CVE-2026-42309MEDIUM5.5Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to...
CVE-2026-42308MEDIUM5.5Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amo...
CVE-2026-8209MEDIUM6.9Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction...
CVE-2026-42295MEDIUM4.9Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve...
CVE-2026-42183MEDIUM6.5Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve...
CVE-2026-42174MEDIUM4.3Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement ...
CVE-2026-42137MEDIUM6.5Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.acc...
CVE-2026-42069MEDIUM6.5Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role...
CVE-2026-42051MEDIUM4.3Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks lice...
CVE-2026-41311MEDIUM6.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular...
CVE-2026-7652MEDIUM5.3The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now