2026 CVE Vulnerabilities

53,346 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-20603MEDIUM4.4This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26.3. An a...
CVE-2026-20602MEDIUM5.5The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8...
CVE-2026-26031MEDIUM5.3Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, ...
CVE-2026-26023MEDIUM6.1Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been foun...
CVE-2026-26019MEDIUM4.1LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langch...
CVE-2026-26012MEDIUM6.5vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35....
CVE-2026-26014MEDIUM5.9Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1...
CVE-2026-25999MEDIUM4.3Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper acces...
CVE-2026-25935MEDIUM5.4Vikunja is a todo-app to organize your life. Prior to 1.1.0, TaskGlanceTooltip.vue temporarily creates a div and sets th...
CVE-2026-25633MEDIUM4.3Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permis...
CVE-2026-25062MEDIUM5.5Outline is a service that allows for collaborative documentation. Prior to 1.4.0, during the JSON import process, the va...
CVE-2026-2323MEDIUM4.3Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform U...
CVE-2026-2322MEDIUM5.4Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinc...
CVE-2026-2320MEDIUM6.5Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinc...
CVE-2026-2318MEDIUM6.5Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who c...
CVE-2026-2317MEDIUM6.5Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cros...
CVE-2026-2316MEDIUM6.5Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform U...
CVE-2026-0229MEDIUM6.6A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® softwa...
CVE-2026-25868MEDIUM6.1MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the d...
CVE-2026-22894MEDIUM6.5A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, th...
CVE-2026-1387MEDIUM6.5GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8...
CVE-2026-1282MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 1...
CVE-2026-1094MEDIUM4.6GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an...
CVE-2026-1080MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 16.7 before 18.6.6, 18.7 before 18.7.4, and 18.8...
CVE-2026-0595MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now