2026 CVE Vulnerabilities

50,977 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-34749MEDIUM5.4Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forg...
CVE-2026-34871MEDIUM6.7An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predict...
CVE-2026-34447MEDIUM5.5Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ...
CVE-2026-34446MEDIUM5.5Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ...
CVE-2026-25834MEDIUM6.5Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
CVE-2026-33978MEDIUM6.1Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerabilit...
CVE-2026-2265MEDIUM6.5An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package...
CVE-2026-20174MEDIUM4.9A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote at...
CVE-2026-20097MEDIUM6.5A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20096MEDIUM6.5A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20095MEDIUM6.5A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20090MEDIUM4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20089MEDIUM4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20088MEDIUM4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20087MEDIUM4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad...
CVE-2026-20085MEDIUM6.1A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to co...
CVE-2026-20042MEDIUM6.5A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encrypt...
CVE-2026-20041MEDIUM6.1A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attac...
CVE-2026-5175MEDIUM5Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti...
CVE-2026-4989MEDIUM4.3Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticate...
CVE-2026-4927MEDIUM6.5Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privi...
CVE-2026-4925MEDIUM5Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra...
CVE-2026-4829MEDIUM5.4Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an ...
CVE-2026-34510MEDIUM6.9OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file...
CVE-2026-30526MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerabil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now