2026 CVE Vulnerabilities

57,015 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13241MEDIUM6.5Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs version...
CVE-2026-13240MEDIUM6.5Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs version...
CVE-2026-13239MEDIUM6.5Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from ...
CVE-2026-13238MEDIUM4.8Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue a...
CVE-2026-13237MEDIUM4.8Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents version...
CVE-2026-13236MEDIUM4.2Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions:...
CVE-2026-13235LOW3.3Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects ...
CVE-2026-13234MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artific...
CVE-2026-13233LOW3.3Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issu...
CVE-2026-13232LOW3.1Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing....
CVE-2026-13231MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Co...
CVE-2026-12535CRITICAL9.8Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field a...
CVE-2026-11909LOW3.3Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examp...
CVE-2026-11908MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allo...
CVE-2026-10770MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam b...
CVE-2026-10769MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Co...
CVE-2026-10768CRITICAL9.8Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov W...
CVE-2026-9726CRITICAL9.8Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal Alternativ...
CVE-2026-7639HIGH7.8Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use afte...
CVE-2026-58499HIGH8.2EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory...
CVE-2026-57807CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Si...
CVE-2026-57575MEDIUM6.9Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Fo...
CVE-2026-57574HIGH7.4Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-...
CVE-2026-57230MEDIUM5.4OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise ed...
CVE-2026-57221MEDIUM5RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform aut...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now