2026 CVE Vulnerabilities

50,909 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-5867MEDIUM4.3Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially se...
CVE-2026-5864MEDIUM4.3Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially...
CVE-2026-5808MEDIUM5.3A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an ...
CVE-2026-5711MEDIUM6.4The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block at...
CVE-2026-40028MEDIUM5.4Hayabusa versions prior to 3.8.0 contain a cross-site scripting (XSS) vulnerability in its HTML report output that allow...
CVE-2026-40025MEDIUM6.1The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where th...
CVE-2026-39901MEDIUM5.7monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity f...
CVE-2026-5803MEDIUM6.3A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The aff...
CVE-2026-5451MEDIUM6.4The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-trac...
CVE-2026-39882MEDIUM5.3OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/log...
CVE-2026-39416MEDIUM6.1AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a store...
CVE-2026-39415MEDIUM4.3Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, ...
CVE-2026-39414MEDIUM6.5MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-...
CVE-2026-39880MEDIUM4.9Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the H...
CVE-2026-39864MEDIUM4.9Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in ...
CVE-2026-39413MEDIUM6.5LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a J...
CVE-2026-35479MEDIUM4.7InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permi...
CVE-2026-35476MEDIUM4.3InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can el...
CVE-2026-39851MEDIUM4.3Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange...
CVE-2026-35455MEDIUM5.4immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripti...
CVE-2026-35407MEDIUM6.5Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and a...
CVE-2026-35403MEDIUM5.4LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-35400MEDIUM4.3LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-35169MEDIUM5.4LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-35165MEDIUM6.5LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now