2026 CVE Vulnerabilities

51,000 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-30527MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Categ...
CVE-2026-5026MEDIUM5.4The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without...
CVE-2026-5025MEDIUM6.5The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log...
CVE-2026-5022MEDIUM5.3The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, a...
CVE-2026-5010MEDIUM5.1A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attac...
CVE-2026-4980MEDIUM6.3A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote at...
CVE-2026-4954MEDIUM6.3A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/m...
CVE-2026-33766MEDIUM6.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs aga...
CVE-2026-33764MEDIUM4.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endp...
CVE-2026-33763MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_corre...
CVE-2026-33761MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in t...
CVE-2026-33759MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.ph...
CVE-2026-33758MEDIUM6.1OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that h...
CVE-2026-33284MEDIUM4.3GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaL...
CVE-2026-33206MEDIUM6.3calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9....
CVE-2026-33205MEDIUM5.5calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9....
CVE-2026-30689MEDIUM4.3In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive ...
CVE-2026-28375MEDIUM6.5A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
CVE-2026-27879MEDIUM6.5A resample query can be used to trigger out-of-memory crashes in Grafana.
CVE-2026-32859MEDIUM5.4ByteDance DeerFlow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts...
CVE-2026-4621MEDIUM5.6Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.
CVE-2026-4309MEDIUM6.5Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device infor...
CVE-2026-25100MEDIUM5.4Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker w...
CVE-2026-3457MEDIUM6.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sent...
CVE-2026-27860MEDIUM5.3If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This l...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now