2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-25220MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-24908MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-24890MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-24487MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-27794MEDIUM6.6LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execu...
CVE-2026-27738MEDIUM6.9The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the i...
CVE-2026-27736MEDIUM6.1BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received wi...
CVE-2026-27705MEDIUM6.5Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in...
CVE-2026-26717MEDIUM4.8An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operat...
CVE-2026-20122MEDIUM5.4A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite a...
CVE-2026-20107MEDIUM5.5A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could all...
CVE-2026-20099MEDIUM6.7A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could a...
CVE-2026-20091MEDIUM4.8A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow ...
CVE-2026-20037MEDIUM4.4A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local atta...
CVE-2026-20036MEDIUM6.5A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated...
CVE-2026-3188MEDIUM4.3A security flaw has been discovered in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This affects an unknown part of the...
CVE-2026-27846MEDIUM6.2Due to missing authentication, a user with physical access to the device can misuse the mesh functionality for adding a ...
CVE-2026-2878MEDIUM5.9In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyn...
CVE-2026-27695MEDIUM5.3zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets...
CVE-2026-27691MEDIUM5.5iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and inclu...
CVE-2026-3186MEDIUM4.3A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unk...
CVE-2026-3185MEDIUM5.5A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /...
CVE-2026-28195MEDIUM4.3In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build confi...
CVE-2026-28194MEDIUM6.1In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow
CVE-2026-28193MEDIUM5.3In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now