2026 CVE Vulnerabilities

51,187 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33136MEDIUM6.1WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)...
CVE-2026-33135MEDIUM6.1WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)...
CVE-2026-33132MEDIUM5.3ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users t...
CVE-2026-32305MEDIUM5.3Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea...
CVE-2026-25792MEDIUM6.5Greenshot is an open source Windows screenshot utility. Versions 1.3.312 and below have untrusted executable search path...
CVE-2026-33130MEDIUM6.5Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9p...
CVE-2026-33129MEDIUM5.9H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability i...
CVE-2026-33123MEDIUM6.5pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious ...
CVE-2026-0677MEDIUM6.3Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injectio...
CVE-2026-3550MEDIUM5.3The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. ...
CVE-2026-33192MEDIUM5.3Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1....
CVE-2026-33080MEDIUM5.4Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and ...
CVE-2026-33070MEDIUM4.8FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, a missing-authentication vulnera...
CVE-2026-2432MEDIUM4.4The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-2421MEDIUM6.5The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an...
CVE-2026-27625MEDIUM6.5Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5...
CVE-2026-23277MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference in ip...
CVE-2026-23276MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: add xmit recursion limit to tunnel xmit functi...
CVE-2026-33065MEDIUM5.3Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1....
CVE-2026-33061MEDIUM5.4Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af5...
CVE-2026-33060MEDIUM5.7CKAN MCP Server is a tool for querying CKAN open data portals. Versions prior to 0.4.85 provide tools including ckan_pac...
CVE-2026-33056MEDIUM6.5tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, th...
CVE-2026-33022MEDIUM6.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Versions 0.60.0 through 1.0.0...
CVE-2026-4476MEDIUM6.3A vulnerability was found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The impacted element is an unknown fun...
CVE-2026-4474MEDIUM6.1A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /adm...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now