2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27223MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2026-2569MEDIUM6.4The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-...
CVE-2026-27270MEDIUM5.5Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to mem...
CVE-2026-27268MEDIUM5.5Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to mem...
CVE-2026-31838MEDIUM5.3Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerabi...
CVE-2026-31833MEDIUM6.7Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Sett...
CVE-2026-31832MEDIUM5.4Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability ex...
CVE-2026-31826MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can cra...
CVE-2026-31825MEDIUM5.3Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrder...
CVE-2026-31824MEDIUM5.9Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was disc...
CVE-2026-31823MEDIUM4.8Sylius is an Open Source eCommerce Framework on Symfony. An authenticated stored cross-site scripting (XSS) vulnerabilit...
CVE-2026-31822MEDIUM6.1Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop c...
CVE-2026-31821MEDIUM5.3Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does n...
CVE-2026-31820MEDIUM6.5Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulner...
CVE-2026-31819MEDIUM6.1Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserContro...
CVE-2026-31815MEDIUM5.3Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipula...
CVE-2026-31812MEDIUM5.3Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, u...
CVE-2026-27221MEDIUM5.5Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Val...
CVE-2026-31809MEDIUM6.1SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attr...
CVE-2026-31808MEDIUM5.3file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in...
CVE-2026-31807MEDIUM6.1SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) blocks dangerous...
CVE-2026-30962MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30954MEDIUM4.3LinkAce is a self-hosted archive to collect website links. In 2.1.0 and earlier, the processTaxonomy() method in LinkRep...
CVE-2026-30953MEDIUM6.5LinkAce is a self-hosted archive to collect website links. When a user creates a link via POST /links, the server fetche...
CVE-2026-30948MEDIUM5.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now