2026 CVE Vulnerabilities

50,998 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33739MEDIUM4.8FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing ta...
CVE-2026-33045MEDIUM5.4Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 20...
CVE-2026-33044MEDIUM5.4Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 20...
CVE-2026-31951MEDIUM5.7LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model ...
CVE-2026-31950MEDIUM5.3LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoi...
CVE-2026-4970MEDIUM6.3A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the...
CVE-2026-34369MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_ap...
CVE-2026-4968MEDIUM4.3A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file ...
CVE-2026-4966MEDIUM6.3A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /ad...
CVE-2026-34368MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `p...
CVE-2026-34364MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, ...
CVE-2026-30568MEDIUM4.8A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in in the v...
CVE-2026-30567MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view...
CVE-2026-4964MEDIUM6.5A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_me...
CVE-2026-34411MEDIUM6.9Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticat...
CVE-2026-34362MEDIUM5.4WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function i...
CVE-2026-34247MEDIUM5.4WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` e...
CVE-2026-34245MEDIUM6.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists...
CVE-2026-30571MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view...
CVE-2026-30570MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view...
CVE-2026-30569MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-4958MEDIUM6.5A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.s...
CVE-2026-32984MEDIUM5.3Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed...
CVE-2026-30527MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Categ...
CVE-2026-5026MEDIUM5.4The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now