2026 CVE Vulnerabilities

53,351 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-25492MEDIUM6.5Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save...
CVE-2026-25491MEDIUM4.8Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type na...
CVE-2026-25480MEDIUM6.5Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to fil...
CVE-2026-25479MEDIUM6.5Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_h...
CVE-2026-25478MEDIUM6.5Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex...
CVE-2026-25230MEDIUM5.4FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an au...
CVE-2026-24900MEDIUM6.5MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, the courses/<:course_...
CVE-2026-24777MEDIUM6.7OpenProject is an open-source, web-based project management software. Prior to 17.0.2, users with the Manage Users permi...
CVE-2026-2242MEDIUM6.1A vulnerability was determined in janet-lang janet up to 1.40.1. This impacts the function janetc_if of the file src/cor...
CVE-2026-2241MEDIUM6.1A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/o...
CVE-2026-21419MEDIUM6.6Dell Display and Peripheral Manager (Windows) versions prior to 2.2 contain an Improper Link Resolution Before File Acce...
CVE-2026-2240MEDIUM6.1A vulnerability has been found in janet-lang janet up to 1.40.1. The impacted element is the function janetc_pop_funcdef...
CVE-2026-24095MEDIUM5.3Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows...
CVE-2026-24027MEDIUM5.3Crafted zones can lead to increased incoming network traffic.
CVE-2026-0398MEDIUM5.3Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
CVE-2026-1960MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'Facebook' parameter in '/loggrodemo/jbrain/Con...
CVE-2026-1959MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes, via the 'descripción' parameter in the '/loggrodemo/...
CVE-2026-0632MEDIUM5.4The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to...
CVE-2026-25847MEDIUM6.1In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
CVE-2026-25846MEDIUM6.5In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
CVE-2026-24098MEDIUM6.5Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or mo...
CVE-2026-22922MEDIUM6.5Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with cust...
CVE-2026-23903MEDIUM5.3Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. ...
CVE-2026-2224MEDIUM5.4A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /syst...
CVE-2026-25916MEDIUM4.3Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now