2026 CVE Vulnerabilities

50,562 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-40242MEDIUM6.5Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/template...
CVE-2026-40191MEDIUM6.8ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta...
CVE-2026-40185MEDIUM6.5TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo m...
CVE-2026-40184MEDIUM5.3TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. Th...
CVE-2026-40178MEDIUM5.9ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a...
CVE-2026-40175MEDIUM4.8Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a...
CVE-2026-39922MEDIUM6.3GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vuln...
CVE-2026-39921MEDIUM6.3GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows a...
CVE-2026-3446MEDIUM6When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded...
CVE-2026-33737MEDIUM6.5Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string()...
CVE-2026-33736MEDIUM6.5Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can en...
CVE-2026-33708MEDIUM6.5Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns...
CVE-2026-33705MEDIUM5.3Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ ...
CVE-2026-33703MEDIUM6.5Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerabili...
CVE-2026-27460MEDIUM6.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a c...
CVE-2026-33141MEDIUM6.5Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerabili...
CVE-2026-32932MEDIUM6.1Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the sess...
CVE-2026-32893MEDIUM5.4Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting (XSS) vulnerability i...
CVE-2026-31941MEDIUM6.5Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request...
CVE-2026-1502MEDIUM5.7CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
CVE-2026-40160MEDIUM6.5PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied UR...
CVE-2026-40159MEDIUM5.5PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows s...
CVE-2026-40103MEDIUM5.4Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's scoped API token enforcement f...
CVE-2026-40100MEDIUM5.3FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitr...
CVE-2026-40086MEDIUM5.3Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the rembg HTTP server al...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now