2026 CVE Vulnerabilities

51,441 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-4241MEDIUM6.3A vulnerability was identified in itsourcecode College Management System 1.0. The impacted element is an unknown functio...
CVE-2026-4238MEDIUM4.7A vulnerability has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing...
CVE-2026-4234MEDIUM6.3A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddControll...
CVE-2026-4233MEDIUM4.3A vulnerability was identified in ThingsGateway 12. This affects an unknown part of the file /api/file/download. The man...
CVE-2026-4230MEDIUM6.3A vulnerability has been found in vanna-ai vanna up to 2.0.2. Affected is the function update_sql of the file src/vanna/...
CVE-2026-4216MEDIUM5.3A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the co...
CVE-2026-4215MEDIUM6.3A security flaw has been discovered in FlowCI flow-core-x up to 1.23.01. The impacted element is the function Save of th...
CVE-2026-4199MEDIUM5.3A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. Affected by this issue is the function insta...
CVE-2026-4198MEDIUM5.3A vulnerability was determined in hypermodel-labs mcp-server-auto-commit 1.0.0. Affected by this vulnerability is the fu...
CVE-2026-4192MEDIUM6.3A vulnerability has been found in AvinashBole quip-mcp-server 1.0.0. Affected by this vulnerability is the function setu...
CVE-2026-4189MEDIUM4.7A weakness has been identified in phpipam up to 1.7.4. The impacted element is an unknown function of the file app/admin...
CVE-2026-4187MEDIUM5.5A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of...
CVE-2026-4185MEDIUM6.3A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swf_d...
CVE-2026-4179MEDIUM6.1Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop.
CVE-2026-4175MEDIUM5.1A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. The affected element is an unknown function of the file ...
CVE-2026-4173MEDIUM6.3A flaw has been found in CodePhiliaX Chat2DB up to 0.3.7. This vulnerability affects the function exportTable/exportTabl...
CVE-2026-4171MEDIUM6.3A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is so...
CVE-2026-4169MEDIUM4.8A security flaw has been discovered in Tecnick TCExam up to 16.6.0. Affected is the function F_xml_export_users of the f...
CVE-2026-3227MEDIUM6.8A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to imprope...
CVE-2026-3111MEDIUM6.9Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuari...
CVE-2026-3024MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma web application, specifically in the endpoint 'vets.wakyma...
CVE-2026-3022MEDIUM6.5Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wa...
CVE-2026-3021MEDIUM6.5Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wa...
CVE-2026-32778MEDIUM5.5libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memo...
CVE-2026-32777MEDIUM5.5libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now