2026 CVE Vulnerabilities

53,154 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27485MEDIUM4.4OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a l...
CVE-2026-27484MEDIUM4.3OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, k...
CVE-2026-27482MEDIUM6.5Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but d...
CVE-2026-27480MEDIUM5.3Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 thro...
CVE-2026-2864MEDIUM5.4A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07...
CVE-2026-27469MEDIUM6.1Isso is a lightweight commenting server written in Python and JavaScript. In commits before 0afbfe0691ee237963e8fb0b2ee0...
CVE-2026-27464MEDIUM6.5Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, aut...
CVE-2026-27458MEDIUM5.4LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting v...
CVE-2026-27452MEDIUM5.3ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In...
CVE-2026-2863MEDIUM5.4A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. T...
CVE-2026-2861MEDIUM5.5A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Chang...
CVE-2026-27210MEDIUM6.1Pannellum is a lightweight, free, and open source panorama viewer for the web. In versions 3.5.0 through 2.5.6, the hot ...
CVE-2026-27205MEDIUM4.3Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session ...
CVE-2026-27199MEDIUM5.3Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Window...
CVE-2026-26047MEDIUM6.5A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimete...
CVE-2026-2860MEDIUM6.3A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d07...
CVE-2026-27196MEDIUM4.8Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-a...
CVE-2026-27193MEDIUM5.3Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5....
CVE-2026-27191MEDIUM6.1Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.3...
CVE-2026-27189MEDIUM5.8OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-a...
CVE-2026-27147MEDIUM5.4GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploa...
CVE-2026-27146MEDIUM4.5GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the admi...
CVE-2026-2490MEDIUM5.5RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows...
CVE-2026-2035MEDIUM6.8Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2026-27133MEDIUM5.9Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. F...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now