2026 CVE Vulnerabilities

67,245 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-94535HIGH7.1lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows auth...
CVE-2026-94534HIGH7.1lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allo...
CVE-2026-94533MEDIUM6.5lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticat...
CVE-2026-94532MEDIUM6.5lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows aut...
CVE-2026-93340MEDIUM6.8Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote ...
CVE-2026-88756MEDIUM5.3Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitte...
CVE-2026-88738HIGH8.8Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload fu...
CVE-2026-79079HIGH7.8An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/...
CVE-2026-78847CRITICAL9.8An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to ...
CVE-2026-78806MEDIUM5.5An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker t...
CVE-2026-65980HIGH7.9Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-61852MEDIUM5.8Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-61851MEDIUM6.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-61743MEDIUM6.3Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-61652HIGH8.7Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issu...
CVE-2026-61541MEDIUM6.9Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests co...
CVE-2026-59830MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-cont...
CVE-2026-59815MEDIUM4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7...
CVE-2026-59814HIGH7.6Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7...
CVE-2026-55210HIGH7.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2...
CVE-2026-46650MEDIUM4.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2...
CVE-2026-17054MEDIUM5.3The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-process...
CVE-2026-15890MEDIUM5.3The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead...
CVE-2026-94588MEDIUM4.4In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is...
CVE-2026-94572CRITICAL9.4In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now