2026 CVE Vulnerabilities

50,301 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6364MEDIUM6.5Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sens...
CVE-2026-6362MEDIUM4.3Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out o...
CVE-2026-6298MEDIUM4.3Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially se...
CVE-2026-40919MEDIUM5.5A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited...
CVE-2026-40918MEDIUM5.5A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of se...
CVE-2026-40916MEDIUM5.5A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a lo...
CVE-2026-39857MEDIUM5.3ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by...
CVE-2026-33889MEDIUM5.4ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site...
CVE-2026-33888MEDIUM5.3ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by...
CVE-2026-21726MEDIUM5.3The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub...
CVE-2026-6383MEDIUM5.4A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly...
CVE-2026-6245MEDIUM5.5A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PA...
CVE-2026-40256MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string pre...
CVE-2026-39845MEDIUM4.1Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr...
CVE-2026-34244MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by...
CVE-2026-33440MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t...
CVE-2026-33220MEDIUM6.8Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo...
CVE-2026-5758MEDIUM6.5JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker ...
CVE-2026-33214MEDIUM4.3Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo...
CVE-2026-6370MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Aj...
CVE-2026-20170MEDIUM6.1A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, ...
CVE-2026-20161MEDIUM5.5A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low ...
CVE-2026-20152MEDIUM5.3A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could all...
CVE-2026-20148MEDIUM4.9A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal a...
CVE-2026-20136MEDIUM6A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now