2026 CVE Vulnerabilities

51,011 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-4346MEDIUM6.8The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of...
CVE-2026-33682MEDIUM4.8Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54....
CVE-2026-33674MEDIUM5.3PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation...
CVE-2026-33673MEDIUM5.4PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cros...
CVE-2026-33672MEDIUM5.3Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj...
CVE-2026-33664MEDIUM5.4Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied fl...
CVE-2026-33658MEDIUM6.5Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-33653MEDIUM5.4Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exis...
CVE-2026-1556MEDIUM6.5Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 ...
CVE-2026-0748MEDIUM4.3In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" ...
CVE-2026-4393MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allows Cross Site Request Forgery.This issue ...
CVE-2026-3532MEDIUM4.2Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation....
CVE-2026-3531MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Au...
CVE-2026-3530MEDIUM4.3Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forg...
CVE-2026-3529MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Google Anal...
CVE-2026-3528MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation...
CVE-2026-3527MEDIUM6.5Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Config...
CVE-2026-3526MEDIUM5.3Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects...
CVE-2026-3525MEDIUM5.3Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects...
CVE-2026-33742MEDIUM5.4Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fiel...
CVE-2026-33738MEDIUM5.4Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored wit...
CVE-2026-33644MEDIUM4.3Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the SSRF protection in `PhotoUrlRule.php` c...
CVE-2026-33638MEDIUM5.3Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/all...
CVE-2026-33635MEDIUM4.3iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in ve...
CVE-2026-33628MEDIUM5.4Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now