2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7814MEDIUM4.8Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controll...
CVE-2026-7813CRITICAL9.9Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Proces...
CVE-2026-6815MEDIUM5.9An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path s...
CVE-2026-6093MEDIUM6Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose record...
CVE-2026-44643CRITICAL10Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an att...
CVE-2026-44201MEDIUM5.3Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and I...
CVE-2026-44200MEDIUM6.5Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim...
CVE-2026-44199MEDIUM6.5Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim...
CVE-2026-44198MEDIUM4.3Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without ...
CVE-2026-44197MEDIUM6.5Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without ...
CVE-2026-42841MEDIUM4.8Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject...
CVE-2026-42613CRITICAL9.4Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attac...
CVE-2026-42612MEDIUM5.4Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/g...
CVE-2026-42611HIGH8.9Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can ...
CVE-2026-42610MEDIUM6.5Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.upda...
CVE-2026-42609HIGH8.1Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows ...
CVE-2026-42608CRITICAL9.1Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash c...
CVE-2026-42607CRITICAL9.1Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achie...
CVE-2026-3320MEDIUM5.1Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input ...
CVE-2026-3319MEDIUM5.1Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input ...
CVE-2026-34092HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne...
CVE-2026-34091HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue ...
CVE-2026-34090HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue ...
CVE-2026-34089HIGH7.5Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2.
CVE-2026-34088HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now