2026 CVE Vulnerabilities

48,605 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-39817MEDIUM5.9The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa...
CVE-2026-8084MEDIUM5.5A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the f...
CVE-2026-44742MEDIUM6.1Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as e...
CVE-2026-41903MEDIUM5.4FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user hold...
CVE-2026-8081MEDIUM6.3A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality...
CVE-2026-36388MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/...
CVE-2026-36387MEDIUM6.5A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This...
CVE-2026-36341MEDIUM5.4Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supp...
CVE-2026-44264MEDIUM4.3Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other...
CVE-2026-44263MEDIUM4.3Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowe...
CVE-2026-41689MEDIUM6Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notifica...
CVE-2026-41687MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in en...
CVE-2026-41650MEDIUM6.1fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version ...
CVE-2026-41519MEDIUM5.4Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions ...
CVE-2026-32686MEDIUM6.9Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The ...
CVE-2026-41685MEDIUM4.3Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by auth...
CVE-2026-41684MEDIUM6.5Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline back...
CVE-2026-41648MEDIUM5Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs...
CVE-2026-41647MEDIUM6.5Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an ...
CVE-2026-5791MEDIUM6.5Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site...
CVE-2026-8080MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows...
CVE-2026-33589MEDIUM6.5Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to ac...
CVE-2026-27415MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in PluginUs.Net BEAR allows Cross Site Request Forgery. This issue affe...
CVE-2026-27421MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elem...
CVE-2026-27416MEDIUM5.3Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Secur...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now