2026 CVE Vulnerabilities

50,848 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33774MEDIUM5.3An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper N...
CVE-2026-33773MEDIUM6.9An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS...
CVE-2026-21904MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2026-40107MEDIUM6.5SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loos...
CVE-2026-35206MEDIUM4.4Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart wi...
CVE-2026-40087MEDIUM5.3LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-str...
CVE-2026-39977MEDIUM6.3flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key take...
CVE-2026-34500MEDIUM6.5CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Ap...
CVE-2026-32990MEDIUM5.3Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects...
CVE-2026-25854MEDIUM6.1Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDraini...
CVE-2026-35195MEDIUM5.4Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco...
CVE-2026-34988MEDIUM6.3Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of it...
CVE-2026-34983MEDIUM5Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free...
CVE-2026-34945MEDIUM6.5Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta...
CVE-2026-34944MEDIUM5.7Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabl...
CVE-2026-34942MEDIUM6.5Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco...
CVE-2026-5329MEDIUM6.5Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring...
CVE-2026-40071MEDIUM5.4pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /j...
CVE-2026-39985MEDIUM6.1LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-39961MEDIUM4.9Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.3...
CVE-2026-39315MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documen...
CVE-2026-35207MEDIUM5.4dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-contr...
CVE-2026-39957MEDIUM4.3Lychee is a free, open-source photo-management tool. Prior to 7.5.4, a SQL operator-precedence bug in SharingController:...
CVE-2026-39943MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revis...
CVE-2026-39856MEDIUM5.5osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulne...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now