2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-51144MEDIUM6.1Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker ...
CVE-2026-18816MEDIUM5A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file...
CVE-2026-70588MEDIUM5Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin fail...
CVE-2026-70493MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built...
CVE-2026-70491MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap...
CVE-2026-70490MEDIUM6.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the termi...
CVE-2026-70489MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio...
CVE-2026-70488MEDIUM4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync ...
CVE-2026-70487MEDIUM5.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di...
CVE-2026-54020MEDIUM6.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolv...
CVE-2026-70484MEDIUM4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac...
CVE-2026-70481MEDIUM5.4Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the stand...
CVE-2026-70480MEDIUM4.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open Web...
CVE-2026-48154MEDIUM5.9GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions pri...
CVE-2026-68743MEDIUM5.5A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length...
CVE-2026-66300MEDIUM5SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. ...
CVE-2026-47763MEDIUM6.8pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm wri...
CVE-2026-47622MEDIUM5.3NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that con...
CVE-2026-47621MEDIUM6.5NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing...
CVE-2026-47620MEDIUM6.5NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing...
CVE-2026-47487MEDIUM4.4NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repos...
CVE-2026-64630MEDIUM5.3A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
CVE-2026-48121MEDIUM6.7@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for sto...
CVE-2026-18785MEDIUM5.3A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Cli...
CVE-2026-18784MEDIUM5.3A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now