2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5189CRITICAL9.8CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unau...
CVE-2026-4857HIGH8.4IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prio...
CVE-2026-40256MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string pre...
CVE-2026-39845MEDIUM4.1Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr...
CVE-2026-34632HIGH8.6Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in ...
CVE-2026-34393HIGH8.8Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limi...
CVE-2026-34244MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by...
CVE-2026-34242HIGH7.7Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded f...
CVE-2026-33667HIGH7.4OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the c...
CVE-2026-33440MEDIUM5Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t...
CVE-2026-33435HIGH8Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial ...
CVE-2026-33220MEDIUM6.8Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo...
CVE-2026-6290CRITICAL9.1Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with...
CVE-2026-5758MEDIUM6.5JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker ...
CVE-2026-33214MEDIUM4.3Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo...
CVE-2026-33212LOW3.1Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending...
CVE-2026-32631HIGH7.4Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent atta...
CVE-2026-30993CRITICAL9.8Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() functio...
CVE-2026-6372HIGH7.5Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configur...
CVE-2026-6370MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Aj...
CVE-2026-30996HIGH7.5An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a direc...
CVE-2026-30995HIGH8.6Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_v...
CVE-2026-30994HIGH7.5Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access...
CVE-2026-20186CRITICAL9.9A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitra...
CVE-2026-20184CRITICAL9.8A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now