2026 CVE Vulnerabilities

43,990 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-55469MEDIUM6.5Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update p...
CVE-2026-55462MEDIUM4.3Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authoriz...
CVE-2026-55461MEDIUM6.1Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the ...
CVE-2026-55370MEDIUM6.4Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verifi...
CVE-2026-54714MEDIUM6.1Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SA...
CVE-2026-15295MEDIUM4.4The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm...
CVE-2026-55843MEDIUM6.5Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission...
CVE-2026-55478MEDIUM5.4Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether th...
CVE-2026-55476MEDIUM4.3Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_...
CVE-2026-55474MEDIUM6.5Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the rout...
CVE-2026-55472MEDIUM4.3Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locati...
CVE-2026-55464MEDIUM5.4Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize jav...
CVE-2026-53449MEDIUM6Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI co...
CVE-2026-15146MEDIUM5.9GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malici...
CVE-2026-57476MEDIUM6.3Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio...
CVE-2026-57475MEDIUM6.9Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed ...
CVE-2026-57474MEDIUM6.9Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accept...
CVE-2026-56666MEDIUM4.8ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch...
CVE-2026-56665MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity m...
CVE-2026-56664MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov...
CVE-2026-59193MEDIUM4.9Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by ...
CVE-2026-59154MEDIUM4.3Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct...
CVE-2026-58493MEDIUM5.1grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by dir...
CVE-2026-57167MEDIUM5.1PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages em...
CVE-2026-55890MEDIUM4.8Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now