2026 CVE Vulnerabilities

53,356 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-2064MEDIUM5.4A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona...
CVE-2026-25727MEDIUM6.5time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided input is provided to any t...
CVE-2026-25642MEDIUM6.1HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.6, files served below th...
CVE-2026-25640MEDIUM5.4Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to befor...
CVE-2026-25651MEDIUM6.1client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Vers...
CVE-2026-25647MEDIUM5.4Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has...
CVE-2026-24418MEDIUM6.5OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e...
CVE-2026-24417MEDIUM6.5OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e...
CVE-2026-24416MEDIUM6.5OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e...
CVE-2026-24050MEDIUM5.4Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profil...
CVE-2026-25723MEDIUM6.5Claude Code is an agentic coding tool. Prior to version 2.0.55, Claude Code failed to properly validate commands using p...
CVE-2026-24903MEDIUM5.4OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was d...
CVE-2026-24776MEDIUM4.3OpenProject is an open-source, web-based project management software. Prior to 17.0.2, the drag&drop handler moving an a...
CVE-2026-24419MEDIUM6.5OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e...
CVE-2026-23633MEDIUM6.5Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via p...
CVE-2026-23632MEDIUM6.5Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/conte...
CVE-2026-22592MEDIUM6.5Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attac...
CVE-2026-1769MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox Centr...
CVE-2026-23739MEDIUM6.5Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1...
CVE-2026-23738MEDIUM6.1Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1...
CVE-2026-1337MEDIUM5.4Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can...
CVE-2026-1293MEDIUM6.4The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-...
CVE-2026-24928MEDIUM5.5Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may a...
CVE-2026-24927MEDIUM5.5Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerabi...
CVE-2026-24924MEDIUM5.5Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now