2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-81162MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience...
CVE-2026-81160MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carou...
CVE-2026-81158MEDIUM5.3Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versi...
CVE-2026-76758MEDIUM5.9Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.
CVE-2026-76757MEDIUM5.9Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-76756MEDIUM5.9Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-76755MEDIUM5.9Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
CVE-2026-73478MEDIUM5.3Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0....
CVE-2026-73477MEDIUM5.3Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versi...
CVE-2026-73476MEDIUM5.4Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This ...
CVE-2026-73474MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This ...
CVE-2026-18986MEDIUM4.8Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Brow...
CVE-2026-16647MEDIUM4.1Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality...
CVE-2026-84835MEDIUM5.3Missing Authorization vulnerability in DimaFreund Rentsyst rentsyst allows Exploiting Incorrectly Configured Access Cont...
CVE-2026-84808MEDIUM4.3Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint...
CVE-2026-84807MEDIUM5.4Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team ...
CVE-2026-84806MEDIUM5.4Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated ...
CVE-2026-84805MEDIUM4.3Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in...
CVE-2026-84804MEDIUM5.4Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and custom...
CVE-2026-84802MEDIUM4.3Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::action...
CVE-2026-84799MEDIUM4.3Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, aut...
CVE-2026-84797MEDIUM6.3Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate()...
CVE-2026-84793MEDIUM4.8Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name fi...
CVE-2026-84792MEDIUM4.3Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements end...
CVE-2026-84781MEDIUM6.5Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now