2026 CVE Vulnerabilities

64,734 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-67230MEDIUM6.3RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the Web STOMP WebSoc...
CVE-2026-67227MEDIUM5.9RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7 and 4.3.1, Atom exhaustion: t...
CVE-2026-67226MEDIUM6.9RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-only atom exhaustion: ...
CVE-2026-67225MEDIUM6.3RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the stream protocol ...
CVE-2026-67223MEDIUM6.3RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance...
CVE-2026-67222MEDIUM5.9RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, mechanisms/1 applied...
CVE-2026-66073MEDIUM6RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, Atom table exha...
CVE-2026-66071MEDIUM6RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom ...
CVE-2026-61837MEDIUM6.3RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQP 1.0 management GET...
CVE-2026-18320MEDIUM6.1Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due ...
CVE-2026-18312MEDIUM6.1Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or...
CVE-2026-18311MEDIUM6.1Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its proces...
CVE-2026-100237MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun...
CVE-2026-97869MEDIUM4.1A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the fun...
CVE-2026-97469MEDIUM4.3PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() ...
CVE-2026-85293MEDIUM4.8InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-bet...
CVE-2026-85292MEDIUM4.8InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-85291MEDIUM6.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-85290MEDIUM5.3InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-85289MEDIUM6.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-85274MEDIUM6.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-54790MEDIUM6InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-39372MEDIUM4.9InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-100230MEDIUM5.3Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, m...
CVE-2026-97866MEDIUM5.6A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now