2026 CVE Vulnerabilities

50,941 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-5704MEDIUM5.5A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to ...
CVE-2026-5666MEDIUM5.5A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionalit...
CVE-2026-34951MEDIUM6.1Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Fo...
CVE-2026-34764MEDIUM5.5Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alph...
CVE-2026-34756MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Servi...
CVE-2026-34755MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO....
CVE-2026-34753MEDIUM5.4vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side re...
CVE-2026-34589MEDIUM5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34380MEDIUM5.9OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34378MEDIUM6.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-33727MEDIUM6.7Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privil...
CVE-2026-33405MEDIUM4.8Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-31354MEDIUM5.4Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 a...
CVE-2026-31353MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attac...
CVE-2026-31352MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allow...
CVE-2026-31351MEDIUM4.8An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo...
CVE-2026-31350MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitra...
CVE-2026-5661MEDIUM5.5A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handle...
CVE-2026-34897MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi...
CVE-2026-33406MEDIUM6.1Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-33404MEDIUM6.1Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-33403MEDIUM6.1Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-32602MEDIUM4.2Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnera...
CVE-2026-31153MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Bynder v0.1.394 allows attackers to execute arbitrary web scripts o...
CVE-2026-31150MEDIUM4.3Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now