2026 CVE Vulnerabilities

57,015 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-55804MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-55803MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-55187MEDIUM5.8Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is ...
CVE-2026-54736HIGH8.2Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the...
CVE-2026-52761MEDIUM5.3ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0....
CVE-2026-52747HIGH8.6ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to ...
CVE-2026-49844MEDIUM5.9Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces ...
CVE-2026-49394HIGH7.1Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_pag...
CVE-2026-49213HIGH8.1TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHtt...
CVE-2026-48127MEDIUM5.3Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach...
CVE-2026-47422MEDIUM5.3Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked approp...
CVE-2026-47199LOW2.3Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT I...
CVE-2026-44795HIGH8.8Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3...
CVE-2026-42219MEDIUM6.9Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was...
CVE-2026-41482HIGH7.1Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion wer...
CVE-2026-15085MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO ...
CVE-2026-15084MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns...
CVE-2026-15083MEDIUM4.2Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Cond...
CVE-2026-15082MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove...
CVE-2026-15081HIGH7.4Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Se...
CVE-2026-15080MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. ...
CVE-2026-15079MEDIUM5.4Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This...
CVE-2026-13244HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Ma...
CVE-2026-13243MEDIUM4.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue...
CVE-2026-13242MEDIUM6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now