2026 CVE Vulnerabilities

43,970 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-58503MEDIUM6.9Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via...
CVE-2026-55808MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core...
CVE-2026-55806MEDIUM5.9URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is...
CVE-2026-55804MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-55803MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-55187MEDIUM5.8Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is ...
CVE-2026-52761MEDIUM5.3ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0....
CVE-2026-49844MEDIUM5.9Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces ...
CVE-2026-48127MEDIUM5.3Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach...
CVE-2026-47422MEDIUM5.3Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked approp...
CVE-2026-42219MEDIUM6.9Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was...
CVE-2026-15085MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO ...
CVE-2026-15084MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns...
CVE-2026-15083MEDIUM4.2Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Cond...
CVE-2026-15082MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove...
CVE-2026-15080MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. ...
CVE-2026-15079MEDIUM5.4Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This...
CVE-2026-13243MEDIUM4.8Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue...
CVE-2026-13242MEDIUM6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation...
CVE-2026-13241MEDIUM6.5Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs version...
CVE-2026-13240MEDIUM6.5Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs version...
CVE-2026-13239MEDIUM6.5Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from ...
CVE-2026-13238MEDIUM4.8Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue a...
CVE-2026-13237MEDIUM4.8Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents version...
CVE-2026-13236MEDIUM4.2Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions:...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now