2026 CVE Vulnerabilities

53,154 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27125MEDIUM6.8svelte performance oriented web framework. Prior to 5.51.5, in server-side rendering, attribute spreading on elements (e...
CVE-2026-27122MEDIUM5.4svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side render...
CVE-2026-27121MEDIUM5.4svelte performance oriented web framework. Versions of svelte prior to 5.51.5 are vulnerable to cross-site scripting (XS...
CVE-2026-27119MEDIUM5.4svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering ou...
CVE-2026-27120MEDIUM6.1Leafkit is a templating language with Swift-inspired syntax. Prior to 1.4.1, htmlEscaped in leaf-kit will only escape ht...
CVE-2026-27118MEDIUM5.3SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Versions of @sveltejs/...
CVE-2026-27113MEDIUM6.3Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and pr...
CVE-2026-27111MEDIUM5Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model incl...
CVE-2026-27026MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can cra...
CVE-2026-27025MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can cra...
CVE-2026-27024MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can cra...
CVE-2026-27022MEDIUM6.5@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection ...
CVE-2026-27020MEDIUM5.3Photobooth prior to 1.0.1 has a cross-site scripting (XSS) vulnerability in user input fields. Malicious users could inj...
CVE-2026-2852MEDIUM6.3A vulnerability was identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects th...
CVE-2026-2851MEDIUM5.3A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This vulnerability af...
CVE-2026-2850MEDIUM6.5A vulnerability was found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function ...
CVE-2026-2832MEDIUM5.3Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing add...
CVE-2026-2849MEDIUM6.3A vulnerability has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issu...
CVE-2026-27506MEDIUM5.4SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user profile update workflow ...
CVE-2026-27505MEDIUM6.1SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user registration workflow (i...
CVE-2026-27504MEDIUM6.1SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in radiomobile_front.php via the ...
CVE-2026-27503MEDIUM6.1SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in admin/log.php via the search q...
CVE-2026-27502MEDIUM6.1SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in log.php via the search query p...
CVE-2026-26745MEDIUM5.3OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration ...
CVE-2026-26100MEDIUM5.5Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now