2026 CVE Vulnerabilities

65,752 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35442HIGH8.1Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (...
CVE-2026-35441MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL end...
CVE-2026-35413MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPE...
CVE-2026-35412HIGH8.1Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumab...
CVE-2026-35411MEDIUM4.3Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerabl...
CVE-2026-35410MEDIUM6.1Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vuln...
CVE-2026-35409HIGH7.7Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request...
CVE-2026-35408CRITICAL9.3Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sig...
CVE-2026-35404MEDIUM6.1Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a...
CVE-2026-22675MEDIUM6.1OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthe...
CVE-2026-5683HIGH8A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter o...
CVE-2026-35472MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the...
CVE-2026-35399MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inj...
CVE-2026-35398MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the...
CVE-2026-35396MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the...
CVE-2026-35395HIGH8.8WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistencia...
CVE-2026-35394HIGH8.8Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-...
CVE-2026-35393CRITICAL9.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. Thi...
CVE-2026-35392CRITICAL9.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitiz...
CVE-2026-35391HIGH7.5Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in...
CVE-2026-35390MEDIUM5.4Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) ...
CVE-2026-35389HIGH7.5Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification...
CVE-2026-35213HIGH7.5@hapi/content provided HTTP Content-* headers parsing. All versions of @hapi/content through 6.0.0 are vulnerable to Reg...
CVE-2026-35208MEDIUM5.4lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML in...
CVE-2026-34972HIGH8.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now