2026 CVE Vulnerabilities

52,221 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-3954MEDIUM6.5A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the ...
CVE-2026-3951MEDIUM4.3A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of...
CVE-2026-32234MEDIUM4.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32095MEDIUM5.4Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.1, Plunk's image upload endpoint accepted S...
CVE-2026-32094MEDIUM6.5Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-brac...
CVE-2026-31974MEDIUM4.3OpenProject is an open-source, web-based project management software. Prior to 17.2.0, OpenProject SMTP test endpoint (P...
CVE-2026-31961MEDIUM5.5Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unb...
CVE-2026-31960MEDIUM5.3Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded r...
CVE-2026-31959MEDIUM5.3Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Serv...
CVE-2026-31901MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 ...
CVE-2026-24508MEDIUM5.5Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerabil...
CVE-2026-31888MEDIUM5.3Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/acc...
CVE-2026-31879MEDIUM5.4Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation ...
CVE-2026-31878MEDIUM5Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a...
CVE-2026-31876MEDIUM5.4Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS...
CVE-2026-24509MEDIUM5.5Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A l...
CVE-2026-31875MEDIUM5.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31868MEDIUM6.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31867MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (I...
CVE-2026-31863MEDIUM4.4Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca...
CVE-2026-31859MEDIUM6.1Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in...
CVE-2026-0231MEDIUM5.7An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obta...
CVE-2026-0230MEDIUM4A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator t...
CVE-2026-3429MEDIUM4.2A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to ...
CVE-2026-31853MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now