2026 CVE Vulnerabilities

52,080 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-22183MEDIUM5.4wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality ...
CVE-2026-1704MEDIUM4.3The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ins...
CVE-2026-0835MEDIUM5.4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2026-2581MEDIUM5.9This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulne...
CVE-2026-1527MEDIUM4.6ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject...
CVE-2026-32269MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32259MEDIUM6.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9...
CVE-2026-32251MEDIUM6.5Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resourc...
CVE-2026-32249MEDIUM5.5Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encoun...
CVE-2026-32240MEDIUM6.5Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: ...
CVE-2026-32239MEDIUM6.5Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length valu...
CVE-2026-32245MEDIUM6.5Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the...
CVE-2026-32237MEDIUM6.5Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to ex...
CVE-2026-32235MEDIUM4.7Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backs...
CVE-2026-32230MEDIUM5.3Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration?...
CVE-2026-32142MEDIUM5.3Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is...
CVE-2026-2376MEDIUM5.4A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal ...
CVE-2026-32139MEDIUM5.4Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload...
CVE-2026-32100MEDIUM5.3Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vul...
CVE-2026-31890MEDIUM5.5Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li...
CVE-2026-31873MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses Strin...
CVE-2026-31860MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML ...
CVE-2026-31841MEDIUM6.5Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0...
CVE-2026-29066MEDIUM6.2Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs....
CVE-2026-24125MEDIUM6.3Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now