2026 CVE Vulnerabilities

64,704 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-100722MEDIUM6.8vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHand...
CVE-2026-94408MEDIUM4.9Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-...
CVE-2026-94400MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-94399MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-...
CVE-2026-94398MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-...
CVE-2026-94397MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-...
CVE-2026-94396MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-...
CVE-2026-82300MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP...
CVE-2026-82294MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP...
CVE-2026-78582MEDIUM6.5Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configure...
CVE-2026-72662MEDIUM6.3Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, ...
CVE-2026-100719MEDIUM6.5Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command t...
CVE-2026-100712MEDIUM6.5froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET r...
CVE-2026-100710MEDIUM4.9Froxlor through 2.3.10 does not filter sensitive columns from API responses: Domains::get(), Domains::listing(), SubDoma...
CVE-2026-100702MEDIUM5.9Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, all...
CVE-2026-100701MEDIUM5.9Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each c...
CVE-2026-100699MEDIUM5.3Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser)...
CVE-2026-100698MEDIUM5.8Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/f...
CVE-2026-100696MEDIUM5.8Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the option...
CVE-2026-100695MEDIUM6.1Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpol...
CVE-2026-100694MEDIUM6.1Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media t...
CVE-2026-100691MEDIUM5.4Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does no...
CVE-2026-100689MEDIUM5.9GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodu...
CVE-2026-100688MEDIUM6.5Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/...
CVE-2026-100687MEDIUM5.5Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table update...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now