2026 CVE Vulnerabilities

52,221 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-3928MEDIUM4.3Insufficient policy enforcement in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced ...
CVE-2026-3927MEDIUM4.3Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform U...
CVE-2026-3925MEDIUM4.3Incorrect security UI in LookalikeChecks in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to...
CVE-2026-32128MEDIUM6.3FastGPT is an AI Agent building platform. In 4.14.7 and earlier, FastGPT's Python Sandbox (fastgpt-sandbox) includes gua...
CVE-2026-32117MEDIUM5.4The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler p...
CVE-2026-3957MEDIUM4.7A flaw has been found in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This vulnerability af...
CVE-2026-3956MEDIUM4.7A vulnerability was detected in xierongwkhd weimai-wetapp up to 5fe9e8225be4f73f2c5087f134aff657bdf1c6f2. This affects t...
CVE-2026-3955MEDIUM6.3A security vulnerability has been detected in elecV2P up to 3.8.3. Affected by this issue is the function runJSFile of t...
CVE-2026-32125MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32124MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32123MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32122MEDIUM4.3OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32121MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32112MEDIUM4.7ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters ...
CVE-2026-32111MEDIUM5.3ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-suppl...
CVE-2026-32109MEDIUM4.4Copyparty is a portable file server. Prior to 1.20.12, if an attacker has been given both read- and write-permissions to...
CVE-2026-32108MEDIUM6.5Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the s...
CVE-2026-32104MEDIUM5.4StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the updateUserNot...
CVE-2026-32102MEDIUM6.5OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live Event...
CVE-2026-32101MEDIUM6.3StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.3.1, the S3 storage ma...
CVE-2026-2640MEDIUM5.5During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a...
CVE-2026-1717MEDIUM6.8An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Ba...
CVE-2026-1653MEDIUM5.5A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could ...
CVE-2026-1652MEDIUM6.1A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could...
CVE-2026-1068MEDIUM5.3An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user ca...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now