2026 CVE Vulnerabilities

50,939 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-35398MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the...
CVE-2026-35396MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the...
CVE-2026-35390MEDIUM5.4Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) ...
CVE-2026-35208MEDIUM5.4lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML in...
CVE-2026-5681MEDIUM6.3A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file ...
CVE-2026-5679MEDIUM5.5A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the functi...
CVE-2026-35201MEDIUM5.9Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed l...
CVE-2026-35200MEDIUM5.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 ...
CVE-2026-35199MEDIUM6.1SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymC...
CVE-2026-35183MEDIUM5.4Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the ...
CVE-2026-35181MEDIUM4.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admi...
CVE-2026-35180MEDIUM4.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/custo...
CVE-2026-35179MEDIUM5.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publ...
CVE-2026-0049MEDIUM6.2In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhausti...
CVE-2026-5675MEDIUM6.3A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /...
CVE-2026-5671MEDIUM4.3A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Im...
CVE-2026-35175MEDIUM6.5Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugi...
CVE-2026-35173MEDIUM6.5Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post...
CVE-2026-35166MEDIUM5.4Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML re...
CVE-2026-35046MEDIUM5.4Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tan...
CVE-2026-30613MEDIUM4.6An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Ver...
CVE-2026-5670MEDIUM6.3A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This is...
CVE-2026-34981MEDIUM5.8The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url...
CVE-2026-34975MEDIUM4.3Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability wa...
CVE-2026-31313MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now