2026 CVE Vulnerabilities

51,002 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27859MEDIUM5.3A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably forma...
CVE-2026-27856MEDIUM5.9Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can u...
CVE-2026-27855MEDIUM5.9Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and usern...
CVE-2026-0394MEDIUM5.3When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or s...
CVE-2026-4948MEDIUM5.5A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D...
CVE-2026-34353MEDIUM5.1In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when un...
CVE-2026-33559MEDIUM5.4WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the af...
CVE-2026-33366MEDIUM6.9Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to for...
CVE-2026-3098MEDIUM6.5The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1...
CVE-2026-4907MEDIUM6.3A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted...
CVE-2026-33730MEDIUM6.5Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2026-33726MEDIUM4.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1....
CVE-2026-33693MEDIUM6.5Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in...
CVE-2026-33697MEDIUM6.3Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulner...
CVE-2026-29071MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8....
CVE-2026-28786MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8....
CVE-2026-33743MEDIUM6.5Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket bac...
CVE-2026-33542MEDIUM4.8Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fing...
CVE-2026-4900MEDIUM5.5A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil...
CVE-2026-4898MEDIUM4.3A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an un...
CVE-2026-4346MEDIUM6.8The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of...
CVE-2026-33682MEDIUM4.8Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54....
CVE-2026-33674MEDIUM5.3PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation...
CVE-2026-33673MEDIUM5.4PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cros...
CVE-2026-33672MEDIUM5.3Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now