2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-39935MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun...
CVE-2026-4065MEDIUM5.4The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing cap...
CVE-2026-39934MEDIUM6.9Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExper...
CVE-2026-39933MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun...
CVE-2026-35568MEDIUM5.7MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk conta...
CVE-2026-34371MEDIUM6.3LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e...
CVE-2026-39401MEDIUM5.4Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processe...
CVE-2026-39400MEDIUM6.1Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user ...
CVE-2026-34080MEDIUM5.5xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassin...
CVE-2026-32712MEDIUM5.4Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to ...
CVE-2026-27949MEDIUM4.3Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentica...
CVE-2026-39841MEDIUM6.1Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi...
CVE-2026-39840MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati...
CVE-2026-39839MEDIUM6.1Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi...
CVE-2026-39838MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati...
CVE-2026-39837MEDIUM5.4Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Car...
CVE-2026-39395MEDIUM5.3Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-...
CVE-2026-39381MEDIUM4.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-a...
CVE-2026-39380MEDIUM5.4Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to ...
CVE-2026-39373MEDIUM5.3JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attac...
CVE-2026-39368MEDIUM6.5WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted a...
CVE-2026-39367MEDIUM5.4WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) featur...
CVE-2026-39366MEDIUM6.5WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/...
CVE-2026-39365MEDIUM5.3Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s hand...
CVE-2026-5762MEDIUM5.3Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Ex...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now