2026 CVE Vulnerabilities

51,187 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33051MEDIUM5.4Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu...
CVE-2026-33041MEDIUM5.3WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the appl...
CVE-2026-33035MEDIUM6.1WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that al...
CVE-2026-32953MEDIUM4.6Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the t...
CVE-2026-32947MEDIUM4.9Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below,...
CVE-2026-4468MEDIUM4.7A vulnerability was determined in Comfast CF-AC100 2.6.0.8. Affected is an unknown function of the file /cgi-bin/mbox-co...
CVE-2026-4136MEDIUM4.3The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up t...
CVE-2026-32941MEDIUM6.5Sliver is a command and control framework that uses a custom Wireguard netstack. Versions 1.7.3 and below contain a Remo...
CVE-2026-32940MEDIUM6.1SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist —...
CVE-2026-32938MEDIUM6.5SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the deskto...
CVE-2026-32114MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, there is a...
CVE-2026-4467MEDIUM4.7A vulnerability was found in Comfast CF-AC100 2.6.0.8. This impacts an unknown function of the file /cgi-bin/mbox-config...
CVE-2026-32937MEDIUM6.5free5GC is an open source 5G core network. free5GC CHF prior to version 1.2.2 has an out-of-bounds slice access vulnerab...
CVE-2026-32935MEDIUM5.9phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, an...
CVE-2026-32889MEDIUM6.5tinytag is a Python library for reading audio file metadata. Version 2.2.0 allows an attacker who can supply MP3 files f...
CVE-2026-31869MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Compos...
CVE-2026-30891MEDIUM6.5Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user cou...
CVE-2026-30889MEDIUM4.9Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderato...
CVE-2026-30888MEDIUM5.5Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a mod...
CVE-2026-4466MEDIUM4.7A vulnerability has been found in Comfast CF-AC100 2.6.0.8. This affects an unknown function of the file /cgi-bin/mbox-c...
CVE-2026-4453MEDIUM4.3Integer overflow in Dawn in Google Chrome on Mac prior to 146.0.7680.153 allowed a remote attacker to leak cross-origin ...
CVE-2026-32881MEDIUM5.3ewe is a Gleam web server. ewe is a Gleam web server. Versions 0.6.0 through 3.0.4 are vulnerable to authentication bypa...
CVE-2026-32880MEDIUM6.4ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type syst...
CVE-2026-32812MEDIUM6.8Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO M...
CVE-2026-32828MEDIUM4.9Kargo manages and automates the promotion of software artifacts. In versions 1.4.0 through 1.6.3, 1.7.0-rc.1 through 1.7...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now