2026 CVE Vulnerabilities

66,317 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61823HIGH7.3code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before...
CVE-2026-57440HIGH7.5The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em...
CVE-2026-56792MEDIUM4.4Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low priv...
CVE-2026-52853MEDIUM5.2Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN ...
CVE-2026-52850MEDIUM4.3Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member...
CVE-2026-48073MEDIUM4.3Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authent...
CVE-2026-48072MEDIUM5.3Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image ...
CVE-2026-48070HIGH7.1Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store att...
CVE-2026-13249CRITICAL9.8An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Hone...
CVE-2026-13248HIGH8.8An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerabil...
CVE-2026-13016CRITICAL9.3ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerab...
CVE-2026-97233LOW3.5A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the f...
CVE-2026-97232MEDIUM6.3A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_fi...
CVE-2026-95985HIGH8.8The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject craft...
CVE-2026-93405MEDIUM6.1Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markd...
CVE-2026-91121MEDIUM5Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlle...
CVE-2026-91120MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlle...
CVE-2026-91119MEDIUM6.4Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-ac...
CVE-2026-85057HIGH8.7ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables t...
CVE-2026-85056HIGH8.2ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser sess...
CVE-2026-81508MEDIUM4.3ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP si...
CVE-2026-71540HIGH7.5Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. F...
CVE-2026-63645HIGH7.5OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoin...
CVE-2026-61816HIGH7.5zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess...
CVE-2026-61815HIGH7.2zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now