2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-88898MEDIUM6.5AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoin...
CVE-2026-88897MEDIUM5.9Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST AP...
CVE-2026-88006MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebU...
CVE-2026-88005MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI...
CVE-2026-85310MEDIUM6.5import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.
CVE-2026-81793MEDIUM6.5Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
CVE-2026-81791MEDIUM6.5Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.
CVE-2026-81788MEDIUM6.3Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.
CVE-2026-81787MEDIUM6.5Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.
CVE-2026-81785MEDIUM6.5Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.
CVE-2026-81782MEDIUM6.5Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.
CVE-2026-81275MEDIUM6.5Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.
CVE-2026-78536MEDIUM6.5Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
CVE-2026-66674MEDIUM5.6Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.
CVE-2026-66632MEDIUM6.5Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.
CVE-2026-15461MEDIUM5.3The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embe...
CVE-2026-88921MEDIUM5.1MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for re...
CVE-2026-88896MEDIUM5.3EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates...
CVE-2026-88894MEDIUM5.4Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the ch...
CVE-2026-88892MEDIUM5OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data impo...
CVE-2026-88884MEDIUM5.8Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0...
CVE-2026-88878MEDIUM5.3Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v...
CVE-2026-88875MEDIUM4.3AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive u...
CVE-2026-88871MEDIUM4.3WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request f...
CVE-2026-88860MEDIUM6.3Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving st...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now