2026 CVE Vulnerabilities

51,177 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33221MEDIUM5.3Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload ha...
CVE-2026-33209MEDIUM6.1Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site script...
CVE-2026-33194MEDIUM6.8SiYuan is a personal knowledge management system. Prior to version 3.6.2, the `IsSensitivePath()` function in `kernel/ut...
CVE-2026-32810MEDIUM5.5Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c...
CVE-2026-32733MEDIUM6.5Halloy is an IRC application written in Rust. Prior to commit 0f77b2cfc5f822517a256ea5a4b94bad8bfe38b6, the DCC receive ...
CVE-2026-32663MEDIUM6.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-31926MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-28204MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-27649MEDIUM6.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-4507MEDIUM6.3A vulnerability was determined in Mindinventory MindSQL up to 0.2.1. The affected element is the function ask_db of the ...
CVE-2026-4506MEDIUM6.3A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core...
CVE-2026-33177MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, low-privileg...
CVE-2026-33171MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticate...
CVE-2026-2378MEDIUM6.5ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content bein...
CVE-2026-33179MEDIUM5.5libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer ...
CVE-2026-33165MEDIUM5libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream ca...
CVE-2026-4505MEDIUM6.3A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh...
CVE-2026-4500MEDIUM6.3A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the fil...
CVE-2026-4438MEDIUM5.4Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the...
CVE-2026-33140MEDIUM6.1PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PyS...
CVE-2026-33126MEDIUM4.3Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3, ...
CVE-2026-4496MEDIUM5.3A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vul...
CVE-2026-32318MEDIUM5.9Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2....
CVE-2026-32317MEDIUM5.9Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to versio...
CVE-2026-32310MEDIUM5.3Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault confi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now