2026 CVE Vulnerabilities

52,730 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-3681MEDIUM6.3A weakness has been identified in welovemedia FFmate up to 2.0.15. This affects the function fireWebhook of the file /in...
CVE-2026-3680MEDIUM6.3A security flaw has been discovered in RyuzakiShinji biome-mcp-server up to 1.0.0. Affected by this issue is some unknow...
CVE-2026-3675MEDIUM5.3A vulnerability was determined in Freedom Factory dGEN1 up to 20260221. Affected by this issue is the function FakeAppRe...
CVE-2026-3674MEDIUM5.3A vulnerability was found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function FakeAp...
CVE-2026-3672MEDIUM6.3A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /j...
CVE-2026-3670MEDIUM5.3A vulnerability was detected in Freedom Factory dGEN1 up to 20260221. Affected is an unknown function of the component c...
CVE-2026-3669MEDIUM5.3A security vulnerability has been detected in Freedom Factory dGEN1 up to 20260221. This impacts the function AlarmServi...
CVE-2026-30859MEDIUM6.5WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0....
CVE-2026-30857MEDIUM5.3WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0....
CVE-2026-30854MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3...
CVE-2026-30850MEDIUM5.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-29196MEDIUM4.3Netmaker makes networks with WireGuard. Prior to version 1.5.0, a user assigned the platform-user role can retrieve Wire...
CVE-2026-29195MEDIUM6.5Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lack...
CVE-2026-3667MEDIUM5.3A security flaw has been discovered in Freedom Factory dGEN1 up to 20260221. The impacted element is the function FakeAp...
CVE-2026-3665MEDIUM5.5A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xl...
CVE-2026-30838MEDIUM6.1league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by i...
CVE-2026-29787MEDIUM5.3mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/d...
CVE-2026-29786MEDIUM6.3node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that p...
CVE-2026-29781MEDIUM6.5Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vul...
CVE-2026-29780MEDIUM5.5eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well...
CVE-2026-29778MEDIUM6.5pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the ed...
CVE-2026-29771MEDIUM6.5Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of ...
CVE-2026-29190MEDIUM5.3Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Tra...
CVE-2026-29076MEDIUM5.9cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib u...
CVE-2026-3664MEDIUM5.5A vulnerability was determined in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_docum...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now