2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-52779MEDIUM5.4OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / au...
CVE-2026-49355MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/ag...
CVE-2026-44736MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint a...
CVE-2026-44735MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares en...
CVE-2026-44734MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization v...
CVE-2026-44733MEDIUM5.9OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on O...
CVE-2026-44732MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a doc...
CVE-2026-44731MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's mee...
CVE-2026-44696MEDIUM5.7OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) r...
CVE-2026-29509MEDIUM5.4Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfi...
CVE-2026-54753MEDIUM5.9Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local H...
CVE-2026-48090MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38...
CVE-2026-47205MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5,...
CVE-2026-55448MEDIUM6.3mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credent...
CVE-2026-54557MEDIUM5.5mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its inst...
CVE-2026-47778MEDIUM4.4Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47775MEDIUM6.8Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47692MEDIUM4.3Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-47207MEDIUM6.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-56823MEDIUM5.4AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-55686MEDIUM5.3Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where...
CVE-2026-48529MEDIUM6GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mo...
CVE-2026-45407MEDIUM5.5Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch comm...
CVE-2026-28385MEDIUM5In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import funct...
CVE-2026-13434MEDIUM4.9A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now