2026 CVE Vulnerabilities

50,998 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-4992MEDIUM4.3A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/op...
CVE-2026-4991MEDIUM5.1A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown funct...
CVE-2026-33996MEDIUM5.5LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS ...
CVE-2026-33992MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download e...
CVE-2026-33936MEDIUM5.3The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El...
CVE-2026-4988MEDIUM5.9A security flaw has been discovered in Open5GS 2.7.6. This issue affects the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6...
CVE-2026-4985MEDIUM5.3A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the ...
CVE-2026-33989MEDIUM6.5Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp...
CVE-2026-33981MEDIUM6.5changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include...
CVE-2026-33954MEDIUM6.5LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-...
CVE-2026-33946MEDIUM5.9MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby S...
CVE-2026-33916MEDIUM4.7Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolve...
CVE-2026-33907MEDIUM6.5Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Respo...
CVE-2026-33904MEDIUM6.5Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification ...
CVE-2026-33903MEDIUM6.5Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted ...
CVE-2026-33887MEDIUM5.4Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticate...
CVE-2026-33886MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions ...
CVE-2026-33885MEDIUM6.1Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external...
CVE-2026-33884MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authentic...
CVE-2026-33883MEDIUM6.1Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:re...
CVE-2026-33882MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown...
CVE-2026-4971MEDIUM4.3A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manip...
CVE-2026-34389MEDIUM6.5Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow w...
CVE-2026-33869MEDIUM4.8Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5...
CVE-2026-33868MEDIUM6.1Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now