2026 CVE Vulnerabilities

51,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33304MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33303MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2026-33299MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32747MEDIUM4.9SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source file...
CVE-2026-27740MEDIUM6.1Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cros...
CVE-2026-27570MEDIUM6.1Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox...
CVE-2026-27491MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coe...
CVE-2026-27454MEDIUM5.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting...
CVE-2026-27166MEDIUM5.4Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficie...
CVE-2026-24299MEDIUM5.3Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-3580MEDIUM4.7In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by...
CVE-2026-3579MEDIUM5.9wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The...
CVE-2026-32119MEDIUM4.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-25928MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-25744MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-3503MEDIUM5.2Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M mi...
CVE-2026-26940MEDIUM6.5Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead De...
CVE-2026-26939MEDIUM6.5Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Resp...
CVE-2026-26933MEDIUM5.7Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Ser...
CVE-2026-26931MEDIUM5.7Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead...
CVE-2026-1005MEDIUM5.3Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryptio...
CVE-2026-32869MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field w...
CVE-2026-32868MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the ...
CVE-2026-32866MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a us...
CVE-2026-4426MEDIUM6.5A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now