2026 CVE Vulnerabilities

50,000 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33431MEDIUM6.5Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POS...
CVE-2026-29647MEDIUM6.5In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state ...
CVE-2026-6550MEDIUM5.7Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and ...
CVE-2026-6060MEDIUM4.5A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a...
CVE-2026-41389MEDIUM6.3OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing ...
CVE-2026-39112MEDIUM5.4Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in ...
CVE-2026-26399MEDIUM5.3A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function...
CVE-2026-23758MEDIUM5.4GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows ...
CVE-2026-23757MEDIUM5.4GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title p...
CVE-2026-23756MEDIUM5.4GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the s...
CVE-2026-23753MEDIUM4.8GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality...
CVE-2026-23752MEDIUM4.8GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editi...
CVE-2026-40098MEDIUM5.4Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-35154MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...
CVE-2026-28684MEDIUM6.6python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, ...
CVE-2026-26951MEDIUM6.7Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-25525MEDIUM4.9Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-6652MEDIUM4.7A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/mod...
CVE-2026-6650MEDIUM4.7A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/Ap...
CVE-2026-3219MEDIUM4.6pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP f...
CVE-2026-34429MEDIUM5.4Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media u...
CVE-2026-25883MEDIUM5.8Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Ve...
CVE-2026-24468MEDIUM5.3OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campa...
CVE-2026-6649MEDIUM6.3A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/...
CVE-2026-6369MEDIUM5.5An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now