2026 CVE Vulnerabilities

50,848 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-40071MEDIUM5.4pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /j...
CVE-2026-39985MEDIUM6.1LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-39961MEDIUM4.9Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.3...
CVE-2026-39315MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documen...
CVE-2026-35207MEDIUM5.4dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-contr...
CVE-2026-39957MEDIUM4.3Lychee is a free, open-source photo-management tool. Prior to 7.5.4, a SQL operator-precedence bug in SharingController:...
CVE-2026-39943MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revis...
CVE-2026-39856MEDIUM5.5osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulne...
CVE-2026-39855MEDIUM5.5osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulner...
CVE-2026-5960MEDIUM4.3A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of th...
CVE-2026-39941MEDIUM6.1ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied inpu...
CVE-2026-35041MEDIUM6.5fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in...
CVE-2026-35040MEDIUM5.3fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in...
CVE-2026-33005MEDIUM4.3Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web se...
CVE-2026-4114MEDIUM6.6Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin ...
CVE-2026-34757MEDIUM4.4LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-3005MEDIUM6.4The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho...
CVE-2026-2519MEDIUM5.3The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation v...
CVE-2026-24661MEDIUM6.5Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which all...
CVE-2026-21388MEDIUM6.5Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which all...
CVE-2026-4901MEDIUM6.5AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker...
CVE-2026-34538MEDIUM6.5Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have ...
CVE-2026-5848MEDIUM4.7A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getCon...
CVE-2026-5847MEDIUM4.3A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file ...
CVE-2026-5840MEDIUM4.7A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now