2026 CVE Vulnerabilities

51,016 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33635MEDIUM4.3iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in ve...
CVE-2026-33628MEDIUM5.4Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item ...
CVE-2026-33621MEDIUM6.5PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.7` throug...
CVE-2026-33620MEDIUM4.3PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.8` throug...
CVE-2026-33619MEDIUM5.5PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab v0.8.3 contains...
CVE-2026-33545MEDIUM6.5MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `m...
CVE-2026-33541MEDIUM6.5TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati...
CVE-2026-33537MEDIUM5Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::from...
CVE-2026-33375MEDIUM6.5The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API rest...
CVE-2026-2272MEDIUM6.5A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the ...
CVE-2026-2271MEDIUM5.5A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnera...
CVE-2026-2239MEDIUM6.5A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing ...
CVE-2026-21724MEDIUM4.3A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API ...
CVE-2026-0967MEDIUM5.5A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could cra...
CVE-2026-0964MEDIUM6.3A malicious SCP server can send unexpected paths that could make the client application override local files outside of ...
CVE-2026-33536MEDIUM4.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9...
CVE-2026-33535MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9...
CVE-2026-33532MEDIUM4.3`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branc...
CVE-2026-33531MEDIUM6.5InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the r...
CVE-2026-33530MEDIUM6.5InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with b...
CVE-2026-33528MEDIUM6.5GoDoxy is a reverse proxy and container orchestrator for self-hosters. Prior to version 0.27.5, the file content API end...
CVE-2026-33525MEDIUM6.1Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-4923MEDIUM5.9Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that...
CVE-2026-3190MEDIUM4.3A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to ...
CVE-2026-33153MEDIUM6.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now