2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-25591MEDIUM6.5New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio...
CVE-2026-25576MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-24484MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-3043MEDIUM6.1A flaw has been found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the fi...
CVE-2026-3063MEDIUM5.4Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a us...
CVE-2026-3028MEDIUM6.1A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file...
CVE-2026-27742MEDIUM5.4Bludit version 3.16.2 contains a stored cross-site scripting (XSS) vulnerability in the post content functionality. The ...
CVE-2026-27741MEDIUM4.3Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /ad...
CVE-2026-3075MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Jeff Starr Simple Ajax Chat ...
CVE-2026-3027MEDIUM6.1A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-...
CVE-2026-23694MEDIUM5.1Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery ...
CVE-2026-23521MEDIUM6.5Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticat...
CVE-2026-26464MEDIUM6.1Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, w...
CVE-2026-2698MEDIUM6.5An improper access control vulnerability exists where an authenticated user could access areas outside of their authoriz...
CVE-2026-27513MEDIUM5.1Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a cross-site request forgery (CSRF) vulnerability...
CVE-2026-27512MEDIUM6.1Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the adm...
CVE-2026-27511MEDIUM5.1Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a clickjacking vulnerability in the web-based adm...
CVE-2026-2985MEDIUM6.3A security flaw has been discovered in Tiandy Video Surveillance System 视频监控平台 7.17.0. This impacts the function downloa...
CVE-2026-2984MEDIUM6.5A vulnerability was identified in SourceCodester Student Result Management System 1.0. This affects an unknown function ...
CVE-2026-26365MEDIUM4Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where...
CVE-2026-2976MEDIUM6.5A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller o...
CVE-2026-2975MEDIUM5.5A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_ap...
CVE-2026-2972MEDIUM5.4A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso...
CVE-2026-2971MEDIUM6.1A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of t...
CVE-2026-2997MEDIUM6.5Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now