2026 CVE Vulnerabilities

49,010 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-4502MEDIUM6.5IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the s...
CVE-2026-41174MEDIUM6.4Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potent...
CVE-2026-40951MEDIUM5.5CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with loc...
CVE-2026-40950MEDIUM6.5CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of...
CVE-2026-40949MEDIUM4.4CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with lo...
CVE-2026-3346MEDIUM6.4IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows...
CVE-2026-3340MEDIUM6.5IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo...
CVE-2026-33452MEDIUM5.5CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with lo...
CVE-2026-33450MEDIUM5.5CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with ...
CVE-2026-28532MEDIUM6.5FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing...
CVE-2026-7429MEDIUM4.6SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attacker...
CVE-2026-40603MEDIUM6.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-35514MEDIUM6.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-32148MEDIUM5.9Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency...
CVE-2026-36766MEDIUM5.4Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer ...
CVE-2026-36763MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 al...
CVE-2026-36761MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers...
CVE-2026-36764MEDIUM5A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows aut...
CVE-2026-36757MEDIUM4.3A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authentica...
CVE-2026-38940MEDIUM6.1Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code ...
CVE-2026-38939MEDIUM6.1Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code...
CVE-2026-36759MEDIUM6.5A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticat...
CVE-2026-36758MEDIUM4.3A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated at...
CVE-2026-36756MEDIUM5.4A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated a...
CVE-2026-7500MEDIUM5.4When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now