2026 CVE Vulnerabilities

57,015 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15089CRITICAL9.1Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*.
CVE-2026-15087MEDIUM5.9vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
CVE-2026-15086MEDIUM5.9vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter...
CVE-2026-14480CRITICAL9.9OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload wor...
CVE-2026-14286Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11915MEDIUM5.9vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions...
CVE-2026-11914MEDIUM5.9vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
CVE-2026-11913CRITICAL9.8vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
CVE-2026-59155MEDIUM6.9Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET ...
CVE-2026-58591MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox al...
CVE-2026-58590MEDIUM5.4Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: f...
CVE-2026-58589MEDIUM5.4Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: f...
CVE-2026-58588MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canv...
CVE-2026-58587MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canv...
CVE-2026-58503MEDIUM6.9Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via...
CVE-2026-57584HIGH8.7Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a def...
CVE-2026-55884CRITICAL9.2Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP...
CVE-2026-55883HIGH8.3Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebS...
CVE-2026-55882HIGH8.3Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD serv...
CVE-2026-55852HIGH8.6Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Imp...
CVE-2026-55810HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphin...
CVE-2026-55809HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance f...
CVE-2026-55808MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core...
CVE-2026-55807LOW3.1Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af...
CVE-2026-55806MEDIUM5.9URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now