2026 CVE Vulnerabilities

43,564 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-45797MEDIUM6.4HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated f...
CVE-2026-45712MEDIUM5.9Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?dat...
CVE-2026-45709MEDIUM5.8Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side R...
CVE-2026-32822MEDIUM6.1dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-26199MEDIUM6.5HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name`...
CVE-2026-26081MEDIUM4.8HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise...
CVE-2026-13724MEDIUM4.3Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an...
CVE-2026-59238MEDIUM6.9Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderA...
CVE-2026-54685MEDIUM5.3FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` a...
CVE-2026-46516MEDIUM4.8Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js...
CVE-2026-45139MEDIUM6.5CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enfo...
CVE-2026-16277MEDIUM6.5A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcin...
CVE-2026-57311MEDIUM5.3Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP...
CVE-2026-57310MEDIUM6.3Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker...
CVE-2026-16244MEDIUM6.3A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerabilit...
CVE-2026-63762MEDIUM6.5SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript...
CVE-2026-63761MEDIUM5.3SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES...
CVE-2026-63758MEDIUM5.4SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenti...
CVE-2026-63753MEDIUM5.3SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At...
CVE-2026-63752MEDIUM5.3SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated ...
CVE-2026-63751MEDIUM5.3SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo...
CVE-2026-63749MEDIUM5.3SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis...
CVE-2026-63748MEDIUM5.3SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac...
CVE-2026-63745MEDIUM5.4SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof compos...
CVE-2026-63744MEDIUM5.1SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redire...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now