2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-28433MEDIUM4.3Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but ...
CVE-2026-1776MEDIUM6.5Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS ...
CVE-2026-3638MEDIUM5.9Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a lo...
CVE-2026-3588MEDIUM5.5A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private ke...
CVE-2026-3089MEDIUM6.5Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to ...
CVE-2026-2919MEDIUM4.3Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _se...
CVE-2026-3819MEDIUM5.4A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown funct...
CVE-2026-21736MEDIUM4.4Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re...
CVE-2026-3817MEDIUM5.5A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects som...
CVE-2026-3816MEDIUM6.5A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function inp...
CVE-2026-25604MEDIUM5.4In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified agai...
CVE-2026-3812MEDIUM6.1A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the fil...
CVE-2026-3822MEDIUM4.8Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing a...
CVE-2026-3766MEDIUM5.4A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an ...
CVE-2026-3763MEDIUM6.1A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown f...
CVE-2026-3761MEDIUM5.4A flaw has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processin...
CVE-2026-3743MEDIUM5.4A flaw has been found in YiFang CMS 2.0.5. This affects the function update of the file app/db/admin/D_singlePageGroup.p...
CVE-2026-3742MEDIUM5.4A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D...
CVE-2026-3741MEDIUM5.4A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file ...
CVE-2026-3739MEDIUM6.3A security flaw has been discovered in suitenumerique messages 0.2.0. This issue affects the function ThreadAccessSerial...
CVE-2026-3738MEDIUM6.3A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknow...
CVE-2026-3737MEDIUM6.3A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of t...
CVE-2026-3733MEDIUM6.3A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/sr...
CVE-2026-3721MEDIUM5.4A weakness has been identified in 1024-lab/lab1024 SmartAdmin up to 3.29. The affected element is an unknown function of...
CVE-2026-3720MEDIUM5.4A security flaw has been discovered in 1024-lab/lab1024 SmartAdmin up to 3.29. Impacted is an unknown function of the fi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now