2026 CVE Vulnerabilities

57,072 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46700MEDIUM4.3Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-serve...
CVE-2026-46672MEDIUM4.6Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in pac...
CVE-2026-44454HIGH8.8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30...
CVE-2026-58468MEDIUM5.5NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows au...
CVE-2026-44877MEDIUM6.5An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960...
CVE-2026-7017HIGH7.1HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server ...
CVE-2026-59800CRITICAL9.89Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-i...
CVE-2026-59708HIGH8.7The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeU...
CVE-2026-55435MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr...
CVE-2026-48958HIGH8.8An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-48957HIGH8.8An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48956MEDIUM5An improper access check allows users to display a list of modules in the frontend.
CVE-2026-48955MEDIUM6.5An improper access check allows unauthorized users to access workflow stage and transition information.
CVE-2026-48954MEDIUM6.1Improper validation leads to a generic XSS vector in the language override feature.
CVE-2026-48953MEDIUM6.1Lack of escaping leads to an XSS vulnerability in the generic image output layout.
CVE-2026-48952MEDIUM6.1Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
CVE-2026-48951MEDIUM6.1Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
CVE-2026-48950MEDIUM6.1Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
CVE-2026-48949MEDIUM6.1Lack of validation leads to an XSS vulnerability in the MFA management views.
CVE-2026-48948HIGH8.8An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2026-48947MEDIUM4.9An improper access check allows privileged users to overwrite media files without editing permissions.
CVE-2026-57851HIGH8.5MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allo...
CVE-2026-23698HIGH8.6Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import featur...
CVE-2026-23697HIGH8.8Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve ...
CVE-2026-14904HIGH7.1AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now