2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-3306MEDIUM4.3An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access ...
CVE-2026-3228MEDIUM6.4The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `...
CVE-2026-31797MEDIUM6.1iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-31794MEDIUM5.5iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-31793MEDIUM5.5iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30986MEDIUM5.5iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30984MEDIUM6.1iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30982MEDIUM6.1iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30981MEDIUM6.1iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30980MEDIUM5.5iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-30974MEDIUM5.4Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of Java...
CVE-2026-30973MEDIUM6.5Appium is an automation framework that provides WebDriver-based automation possibilities for a wide range platforms. Pri...
CVE-2026-30964MEDIUM5.4web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that ...
CVE-2026-30959MEDIUM5OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any au...
CVE-2026-30942MEDIUM6.5Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to 1.7.3, an ...
CVE-2026-30938MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.12 ...
CVE-2026-30934MEDIUM5.4FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is ...
CVE-2026-30897MEDIUM6.6A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, Fort...
CVE-2026-2742MEDIUM5.3An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24...
CVE-2026-2741MEDIUM6.8Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Va...
CVE-2026-27661MEDIUM5.3A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks co...
CVE-2026-26144MEDIUM4.7Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an...
CVE-2026-25972MEDIUM6.1An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS...
CVE-2026-25689MEDIUM6.5An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec...
CVE-2026-25572MEDIUM5.5A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component doe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now