2026 CVE Vulnerabilities

53,635 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-22030MEDIUM6.5React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through...
CVE-2026-22029MEDIUM6.1React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, ...
CVE-2026-22605MEDIUM4.3OpenProject is an open-source, web-based project management software. OpenProject versions prior to version 16.6.3, allo...
CVE-2026-22604MEDIUM5.3OpenProject is an open-source, web-based project management software. For OpenProject versions from 11.2.1 to before 16....
CVE-2026-22603MEDIUM6.5OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, OpenProject’s unauthentic...
CVE-2026-22027MEDIUM6CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2026-22024MEDIUM5.3CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2026-21900MEDIUM5.9CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2026-21899MEDIUM4.9CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2026-22198MEDIUM6.1GestSup versions prior to 3.2.60 contain a pre-authentication stored cross-site scripting (XSS) vulnerability in the API...
CVE-2026-0817MEDIUM5.3Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse....
CVE-2026-0627MEDIUM6.4The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up...
CVE-2026-20975MEDIUM5.5Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access s...
CVE-2026-20974MEDIUM4.6Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attack...
CVE-2026-20969MEDIUM5.5Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with syste...
CVE-2026-20968MEDIUM6.7Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.
CVE-2026-0563MEDIUM6.4The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Store...
CVE-2026-22713MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2026-22712MEDIUM4.3Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia ...
CVE-2026-22710MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2026-0730MEDIUM4.8A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UP...
CVE-2026-22588MEDIUM6.5Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5,...
CVE-2026-22253MEDIUM5.4Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the L...
CVE-2026-21860MEDIUM5.3Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows p...
CVE-2026-22587MEDIUM5.5Ideagen DevonWay contains a stored cross site scripting vulnerability. A remote, authenticated attacker could craft a pa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now