2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-18738MEDIUM4.7Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote att...
CVE-2026-18736MEDIUM5.3Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the serve...
CVE-2026-18648MEDIUM5.3A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat...
CVE-2026-18646MEDIUM5.5A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system...
CVE-2026-18645MEDIUM5.4A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sys...
CVE-2026-69198MEDIUM6.9ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, ev...
CVE-2026-66296MEDIUM5.1Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-sit...
CVE-2026-62354MEDIUM4.3Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit...
CVE-2026-58139MEDIUM6.5The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with S...
CVE-2026-18654MEDIUM6.9Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v...
CVE-2026-18644MEDIUM5.4A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /...
CVE-2026-18632MEDIUM6.3A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of ...
CVE-2026-18631MEDIUM6.3A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig ...
CVE-2026-38446MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread e...
CVE-2026-38444MEDIUM6.1osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is...
CVE-2026-69153MEDIUM5.3PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ...
CVE-2026-69151MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-69149MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-68945MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-68930MEDIUM6.5Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reci...
CVE-2026-67612MEDIUM4.8OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al...
CVE-2026-18610MEDIUM5.5A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.asp...
CVE-2026-18604MEDIUM5.3A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function D...
CVE-2026-18477MEDIUM4.4A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a...
CVE-2026-18243MEDIUM6.9Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now