2026 CVE Vulnerabilities

51,198 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-4453MEDIUM4.3Integer overflow in Dawn in Google Chrome on Mac prior to 146.0.7680.153 allowed a remote attacker to leak cross-origin ...
CVE-2026-32881MEDIUM5.3ewe is a Gleam web server. ewe is a Gleam web server. Versions 0.6.0 through 3.0.4 are vulnerable to authentication bypa...
CVE-2026-32880MEDIUM6.4ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type syst...
CVE-2026-32812MEDIUM6.8Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO M...
CVE-2026-32828MEDIUM4.9Kargo manages and automates the promotion of software artifacts. In versions 1.4.0 through 1.6.3, 1.7.0-rc.1 through 1.7...
CVE-2026-32766MEDIUM5.3astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.6 and earlier, malformed PAX e...
CVE-2026-32761MEDIUM6.5File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-32758MEDIUM6.5File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-32757MEDIUM5.4Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POS...
CVE-2026-32697MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29108MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-22737MEDIUM5.9Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications c...
CVE-2026-33395MEDIUM5.4Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the discou...
CVE-2026-32818MEDIUM6.5Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does no...
CVE-2026-32816MEDIUM5.7Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivat...
CVE-2026-32755MEDIUM5.7Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/p...
CVE-2026-32721MEDIUM4.8LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerabil...
CVE-2026-29107MEDIUM5.3SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29106MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29105MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29100MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15....
CVE-2026-29098MEDIUM4.9SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29096MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-33410MEDIUM5.4Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two au...
CVE-2026-33393MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now