2026 CVE Vulnerabilities

45,065 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-13455MEDIUM4.3PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() ...
CVE-2026-4360MEDIUM5.3In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy...
CVE-2026-48192MEDIUM6.8A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), M...
CVE-2026-44947MEDIUM6.9A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13....
CVE-2026-27956MEDIUM4.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27955MEDIUM6.6Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27883MEDIUM5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27882MEDIUM4.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27881MEDIUM5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-35098MEDIUM6.9KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform ...
CVE-2026-35097MEDIUM6.9KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic,...
CVE-2026-35096MEDIUM5.1KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functio...
CVE-2026-35095MEDIUM4.8KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid...
CVE-2026-14178MEDIUM5.9openGauss 在处理带 NLS 参数的 to_timestamp 调用时,to_timestamp_with_fmt_nls() 会将 nls_fmt_str 保存到 u_sess->parser_cxt.nls_fmt_str。在 ...
CVE-2026-8403MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electroni...
CVE-2026-4629MEDIUM6.5A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability b...
CVE-2026-14209MEDIUM4.3A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass secur...
CVE-2026-12388MEDIUM6.5A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user informati...
CVE-2026-57082MEDIUM5.9Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG...
CVE-2026-57079MEDIUM5.3Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-sup...
CVE-2026-53692MEDIUM5.9Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographical...
CVE-2026-52760MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A...
CVE-2026-13316MEDIUM4.4A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Atta...
CVE-2026-6954MEDIUM5.1Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to...
CVE-2026-6953MEDIUM5.1HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an ema...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now