2026 CVE Vulnerabilities

60,112 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52785CRITICAL9.9OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection ...
CVE-2026-52784HIGH8.8OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET...
CVE-2026-52783HIGH8.2OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages mo...
CVE-2026-52782CRITICAL9.9OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through ...
CVE-2026-52781MEDIUM6.4OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants...
CVE-2026-52780CRITICAL9.6OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning lea...
CVE-2026-52779MEDIUM5.4OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / au...
CVE-2026-49991HIGH8.6RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject pe...
CVE-2026-49355MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/ag...
CVE-2026-47193HIGH7.5OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint...
CVE-2026-46386CRITICAL9.9OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docke...
CVE-2026-44736MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint a...
CVE-2026-44735MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares en...
CVE-2026-44734MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization v...
CVE-2026-44733MEDIUM5.9OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on O...
CVE-2026-44732MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a doc...
CVE-2026-44731MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's mee...
CVE-2026-44696MEDIUM5.7OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) r...
CVE-2026-32833HIGH8.8Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authe...
CVE-2026-29509MEDIUM5.4Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfi...
CVE-2026-54753MEDIUM5.9Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local H...
CVE-2026-48090MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38...
CVE-2026-47220HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38...
CVE-2026-47205MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5,...
CVE-2026-13372HIGH7.2Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now