2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-90452MEDIUM6Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exch...
CVE-2026-90450MEDIUM5.3The application's role-authorization lookup defaults to granting access when a request handler's name is not present in ...
CVE-2026-90449MEDIUM6.9When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party admin...
CVE-2026-90446MEDIUM5.3An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path o...
CVE-2026-90443MEDIUM5.3A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate e...
CVE-2026-54258MEDIUM6.5ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and...
CVE-2026-54248MEDIUM6.5Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and...
CVE-2026-50018MEDIUM6.5Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClie...
CVE-2026-49992MEDIUM6.3Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request for...
CVE-2026-48496MEDIUM6.2OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages...
CVE-2026-45056MEDIUM6.9matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix cli...
CVE-2026-81918MEDIUM4.8Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A us...
CVE-2026-81917MEDIUM5.4Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the ...
CVE-2026-68535MEDIUM4.3Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's vali...
CVE-2026-54165MEDIUM6.4Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click st...
CVE-2026-50025MEDIUM6.9Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mous...
CVE-2026-49865MEDIUM5.3Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulner...
CVE-2026-49439MEDIUM4.3OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoin...
CVE-2026-48490MEDIUM6.9ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in ...
CVE-2026-45057MEDIUM4.9matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matri...
CVE-2026-89332MEDIUM5.5Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version...
CVE-2026-81916MEDIUM4.3Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the po...
CVE-2026-81915MEDIUM5.3Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::s...
CVE-2026-81913MEDIUM6.1Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft...
CVE-2026-81912MEDIUM5.7Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now