2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-73432MEDIUM5.1Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization ...
CVE-2026-73405MEDIUM5.3An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to S...
CVE-2026-73374MEDIUM6.1A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter ...
CVE-2026-73290MEDIUM5.3RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions req...
CVE-2026-73288MEDIUM6.1RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crat...
CVE-2026-73287MEDIUM5.4RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriv...
CVE-2026-73265MEDIUM6.5RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, Co...
CVE-2026-73262MEDIUM5.4Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html....
CVE-2026-68760MEDIUM5.3An unauthenticated user may bypass authentication under specific cache conditions.
CVE-2026-68756MEDIUM6.6A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
CVE-2026-68755MEDIUM4.3A bundle writer may create misleading release promotion information under specific conditions.
CVE-2026-68754MEDIUM6.5A repository publisher without delete permission may modify protected package content under specific conditions.
CVE-2026-68753MEDIUM5.3An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in...
CVE-2026-67287MEDIUM6.3Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated att...
CVE-2026-67286MEDIUM6.3Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8...
CVE-2026-66382MEDIUM4.3An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVE-2026-66381MEDIUM5.3A repository reader with cache-deploy permission may access content outside a configured upstream path under specific co...
CVE-2026-66380MEDIUM4.3An authenticated user without repository read permission may access private OCI referrer metadata under specific conditi...
CVE-2026-66379MEDIUM4.3An authenticated user may view private Puppet module metadata without repository read access.
CVE-2026-66378MEDIUM4.3An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66377MEDIUM5.3An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-66376MEDIUM4.2Credentials for a deleted user may remain valid for a short period under specific conditions.
CVE-2026-49349MEDIUM6.8regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert...
CVE-2026-47234MEDIUM4.4Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se...
CVE-2026-47233MEDIUM6.5Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now