2026 CVE Vulnerabilities

44,013 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-55464MEDIUM5.4Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize jav...
CVE-2026-53449MEDIUM6Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI co...
CVE-2026-15146MEDIUM5.9GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malici...
CVE-2026-57476MEDIUM6.3Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio...
CVE-2026-57475MEDIUM6.9Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed ...
CVE-2026-57474MEDIUM6.9Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accept...
CVE-2026-56666MEDIUM4.8ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch...
CVE-2026-56665MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity m...
CVE-2026-56664MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov...
CVE-2026-59193MEDIUM4.9Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by ...
CVE-2026-59154MEDIUM4.3Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct...
CVE-2026-58493MEDIUM5.1grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by dir...
CVE-2026-57167MEDIUM5.1PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages em...
CVE-2026-55890MEDIUM4.8Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media ...
CVE-2026-55885MEDIUM6.8Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download ...
CVE-2026-55669MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov...
CVE-2026-3251MEDIUM6.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul...
CVE-2026-15377MEDIUM4.3A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown fun...
CVE-2026-15376MEDIUM6.3A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/...
CVE-2026-8595MEDIUM5.4A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that ex...
CVE-2026-46388MEDIUM4.4osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unpr...
CVE-2026-15375MEDIUM4.3A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /ca...
CVE-2026-15374MEDIUM6.3A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/rol...
CVE-2026-15373MEDIUM6.3A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the...
CVE-2026-61492MEDIUM6.1In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now