2026 CVE Vulnerabilities

57,021 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56668HIGH8.1ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for ur...
CVE-2026-56667HIGH7.3ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPreconditi...
CVE-2026-56666MEDIUM4.8ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch...
CVE-2026-56665MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity m...
CVE-2026-56664MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov...
CVE-2026-55672HIGH7.4ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchan...
CVE-2026-55671LOW2.3ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification chan...
CVE-2026-55670LOW2.3ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the...
CVE-2026-53780Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-2397CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automa...
CVE-2026-59193MEDIUM4.9Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by ...
CVE-2026-59190HIGH8.7grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.5...
CVE-2026-59180LOW3.1Apprise is an open source library which allows you to send a notification to almost all of the most popular notification...
CVE-2026-59162HIGH7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses...
CVE-2026-59161HIGH7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming w...
CVE-2026-59154MEDIUM4.3Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct...
CVE-2026-58493MEDIUM5.1grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by dir...
CVE-2026-58492CRITICAL9.2grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its t...
CVE-2026-57167MEDIUM5.1PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages em...
CVE-2026-56675HIGH8.39Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* acce...
CVE-2026-55890MEDIUM4.8Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media ...
CVE-2026-55885MEDIUM6.8Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download ...
CVE-2026-55783LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-hous...
CVE-2026-55782LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly a...
CVE-2026-55781LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now