2026 CVE Vulnerabilities

43,635 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-48008MEDIUM6.5Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL...
CVE-2026-63309MEDIUM4.3SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to...
CVE-2026-63308MEDIUM6.5Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template help...
CVE-2026-49216MEDIUM5.4Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/...
CVE-2026-49215MEDIUM5.4Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventList...
CVE-2026-49210MEDIUM6.1Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\Child...
CVE-2026-49209MEDIUM6.5Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller...
CVE-2026-49208MEDIUM5.3Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as Date...
CVE-2026-44722MEDIUM6.2pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python...
CVE-2026-21764MEDIUM4.3HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric...
CVE-2026-21762MEDIUM5.3HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag...
CVE-2026-21761MEDIUM5.4HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may ...
CVE-2026-21760MEDIUM4.6HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a...
CVE-2026-16108MEDIUM6.5A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible...
CVE-2026-16106MEDIUM4.9A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when...
CVE-2026-16104MEDIUM6.5A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engi...
CVE-2026-16103MEDIUM4.3A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher...
CVE-2026-16093MEDIUM5.4Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them...
CVE-2026-11763MEDIUM6.5Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D ...
CVE-2026-9537MEDIUM5.3Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode()...
CVE-2026-63098MEDIUM6.9TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated atta...
CVE-2026-63097MEDIUM5.3Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/rout...
CVE-2026-63096MEDIUM6.9Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to ca...
CVE-2026-58149MEDIUM5.3Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking i...
CVE-2026-15783MEDIUM5.3A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now