2026 CVE Vulnerabilities

53,351 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-25905MEDIUM5.8The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any ...
CVE-2026-25904MEDIUM5.8The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the ...
CVE-2026-2222MEDIUM4.8A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown...
CVE-2026-2216MEDIUM4.3A flaw has been found in rachelos WeRSS we-mp-rss up to 1.4.8. Impacted is the function download_export_file of the file...
CVE-2026-22613MEDIUM5.7The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potential...
CVE-2026-2214MEDIUM4.8A weakness has been identified in code-projects for Plugin 1.0. This affects an unknown part of the file /Administrator/...
CVE-2026-2201MEDIUM5.4A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. Thi...
CVE-2026-2200MEDIUM4.8A weakness has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/sav...
CVE-2026-2160MEDIUM6.1A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability i...
CVE-2026-2159MEDIUM6.1A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the fi...
CVE-2026-2156MEDIUM4.8A weakness has been identified in code-projects Online Student Management System 1.0. The impacted element is an unknown...
CVE-2026-2154MEDIUM6.1A vulnerability was identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Impact...
CVE-2026-2153MEDIUM6.1A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the f...
CVE-2026-2150MEDIUM6.1A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by thi...
CVE-2026-2149MEDIUM6.1A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected...
CVE-2026-2147MEDIUM5.5A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/Download...
CVE-2026-2145MEDIUM5.4A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the fil...
CVE-2026-2209MEDIUM4.3A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file ...
CVE-2026-2208MEDIUM6.5A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publi...
CVE-2026-2207MEDIUM6.9A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/public...
CVE-2026-2205MEDIUM5.3A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.j...
CVE-2026-25568MEDIUM4.3WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allow...
CVE-2026-25567MEDIUM4.3WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The en...
CVE-2026-25566MEDIUM5.4WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination...
CVE-2026-25565MEDIUM6.5WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only bo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now