2026 CVE Vulnerabilities

66,998 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-77320MEDIUM5.3TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns...
CVE-2026-77294HIGH8.1TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlle...
CVE-2026-77293HIGH7.1TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId...
CVE-2026-65827MEDIUM6.5Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated worksp...
CVE-2026-62286MEDIUM4.3Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a...
CVE-2026-61825HIGH8.7code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before...
CVE-2026-61823HIGH7.3code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before...
CVE-2026-57440HIGH7.5The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em...
CVE-2026-56792MEDIUM4.4Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low priv...
CVE-2026-52853MEDIUM5.2Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN ...
CVE-2026-52850MEDIUM4.3Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member...
CVE-2026-48073MEDIUM4.3Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authent...
CVE-2026-48072MEDIUM5.3Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image ...
CVE-2026-48070HIGH7.1Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store att...
CVE-2026-13249CRITICAL9.8An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Hone...
CVE-2026-13248HIGH8.8An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerabil...
CVE-2026-13016CRITICAL9.3ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerab...
CVE-2026-97233LOW3.5A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the f...
CVE-2026-97232MEDIUM6.3A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_fi...
CVE-2026-95985HIGH8.8The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject craft...
CVE-2026-93405MEDIUM6.1Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markd...
CVE-2026-91121MEDIUM5Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlle...
CVE-2026-91120MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlle...
CVE-2026-91119MEDIUM6.4Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-ac...
CVE-2026-85057HIGH8.7ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now