2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-72744MEDIUM6.9Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the ...
CVE-2026-59693MEDIUM5.3A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01....
CVE-2026-72610MEDIUM4.3A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta...
CVE-2026-72608MEDIUM6.5A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta...
CVE-2026-72604MEDIUM6.5A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete ar...
CVE-2026-72598MEDIUM6.5A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the se...
CVE-2026-72597MEDIUM6.5A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with ...
CVE-2026-72560MEDIUM6.5A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTI...
CVE-2026-72559MEDIUM5.4A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent...
CVE-2026-72554MEDIUM6.5A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer ...
CVE-2026-72553MEDIUM5.4A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persisten...
CVE-2026-72549MEDIUM5.3An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ...
CVE-2026-72542MEDIUM5.4A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write ...
CVE-2026-72541MEDIUM6.5A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe...
CVE-2026-72540MEDIUM4.3An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid prev...
CVE-2026-72539MEDIUM6.5An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem...
CVE-2026-73162MEDIUM5.3Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /acco...
CVE-2026-33922MEDIUM6.8A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to in...
CVE-2026-33921MEDIUM5.2The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver ...
CVE-2026-73161MEDIUM5.1Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feat...
CVE-2026-73159MEDIUM5.1Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's ...
CVE-2026-73158MEDIUM5.1Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can cont...
CVE-2026-71218MEDIUM5.3A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function,...
CVE-2026-73156MEDIUM5.3Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap t...
CVE-2026-73155MEDIUM5.3Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now