2026 CVE Vulnerabilities

64,704 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-101033MEDIUM4.3KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operati...
CVE-2026-100869MEDIUM5.9Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing cust...
CVE-2026-100868MEDIUM6.3Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in si...
CVE-2026-97165MEDIUM5.3Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” par...
CVE-2026-100749MEDIUM5.1Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned fi...
CVE-2026-100748MEDIUM6.9Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0
CVE-2026-100747MEDIUM5.1Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF toke...
CVE-2026-93304MEDIUM6.3A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has...
CVE-2026-89135MEDIUM6.3A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certifi...
CVE-2026-89134MEDIUM6.3A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN ...
CVE-2026-89133MEDIUM6.3wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly e...
CVE-2026-100863MEDIUM5Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/serv...
CVE-2026-100862MEDIUM4.9heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0...
CVE-2026-100861MEDIUM5heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowin...
CVE-2026-100860MEDIUM5.5heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backen...
CVE-2026-100859MEDIUM6.5Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that all...
CVE-2026-100858MEDIUM6.8heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nod...
CVE-2026-100855MEDIUM6.5AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}...
CVE-2026-100854MEDIUM6.3AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derive...
CVE-2026-100853MEDIUM5.9In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allow...
CVE-2026-100836MEDIUM4.3Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSO...
CVE-2026-100834MEDIUM5.9http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0....
CVE-2026-100745MEDIUM6.3A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform...
CVE-2026-100725MEDIUM6.5http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (clien...
CVE-2026-100724MEDIUM5.4http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now