2026 CVE Vulnerabilities

48,605 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8119MEDIUM5.5A vulnerability was detected in Open5GS up to 2.7.7. Impacted is the function ogs_sbi_stream_find_by_id in the library /...
CVE-2026-8117MEDIUM4.3A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects some unkno...
CVE-2026-8116MEDIUM6.3A weakness has been identified in huangjunsen0406 xiaozhi-mcphub up to 1.0.3. This vulnerability affects unknown code of...
CVE-2026-8115MEDIUM5.5A security flaw has been discovered in gyoridavid short-video-maker up to 1.3.4. This affects an unknown part of the fil...
CVE-2026-8114MEDIUM6.3A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the fil...
CVE-2026-8113MEDIUM6.5A vulnerability was determined in 8421bit MiniClaw up to 43905b934cf76489ab28e4d17da28ee97970f91f. Affected by this vuln...
CVE-2026-8106MEDIUM6.1A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page th...
CVE-2026-6736MEDIUM6.5An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attack...
CVE-2026-41929MEDIUM6.1Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor previ...
CVE-2026-41928MEDIUM6.9Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated...
CVE-2026-40214MEDIUM6.3In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. Th...
CVE-2026-33823MEDIUM6.5Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
CVE-2026-32207MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an...
CVE-2026-8097MEDIUM6.3A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the fi...
CVE-2026-41692MEDIUM4.7i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes....
CVE-2026-8142MEDIUM6.5VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use...
CVE-2026-8088MEDIUM5.5A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the ...
CVE-2026-43510MEDIUM5.9manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assi...
CVE-2026-42259MEDIUM5.1Saltcorn is an extensible, open source, no-code database application builder. Prior to versions 1.4.6, 1.5.6, and 1.6.0-...
CVE-2026-42241MEDIUM5.3ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to before version 23.0....
CVE-2026-42225MEDIUM5.9PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, ...
CVE-2026-39826MEDIUM6.1If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit...
CVE-2026-39825MEDIUM5.3ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite functi...
CVE-2026-39823MEDIUM6.1CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribu...
CVE-2026-39819MEDIUM5.3The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp")....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now