2026 CVE Vulnerabilities

50,680 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-35195MEDIUM5.4Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco...
CVE-2026-34988MEDIUM6.3Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of it...
CVE-2026-34983MEDIUM5Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free...
CVE-2026-34945MEDIUM6.5Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta...
CVE-2026-34944MEDIUM5.7Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabl...
CVE-2026-34942MEDIUM6.5Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco...
CVE-2026-5329MEDIUM6.5Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring...
CVE-2026-40071MEDIUM5.4pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /j...
CVE-2026-39985MEDIUM6.1LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-39961MEDIUM4.9Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.3...
CVE-2026-39315MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documen...
CVE-2026-35207MEDIUM5.4dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-contr...
CVE-2026-39957MEDIUM4.3Lychee is a free, open-source photo-management tool. Prior to 7.5.4, a SQL operator-precedence bug in SharingController:...
CVE-2026-39943MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revis...
CVE-2026-39856MEDIUM5.5osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulne...
CVE-2026-39855MEDIUM5.5osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulner...
CVE-2026-5960MEDIUM4.3A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of th...
CVE-2026-39941MEDIUM6.1ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied inpu...
CVE-2026-35041MEDIUM6.5fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in...
CVE-2026-35040MEDIUM5.3fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in...
CVE-2026-33005MEDIUM4.3Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web se...
CVE-2026-4114MEDIUM6.6Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin ...
CVE-2026-34757MEDIUM4.4LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-3005MEDIUM6.4The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho...
CVE-2026-2519MEDIUM5.3The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now