2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52779 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / au... |
| CVE-2026-49355 | MEDIUM | 4.3 | 0.2% | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/ag... |
| CVE-2026-44736 | MEDIUM | 6.5 | — | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint a... |
| CVE-2026-44735 | MEDIUM | 6.5 | 0.3% | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares en... |
| CVE-2026-44734 | MEDIUM | 6.5 | — | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization v... |
| CVE-2026-44733 | MEDIUM | 5.9 | 0.2% | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on O... |
| CVE-2026-44732 | MEDIUM | 4.3 | 0.2% | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a doc... |
| CVE-2026-44731 | MEDIUM | 4.3 | 0.2% | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's mee... |
| CVE-2026-44696 | MEDIUM | 5.7 | — | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) r... |
| CVE-2026-29509 | MEDIUM | 5.4 | 0.3% | Jun 26, 2026 | Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfi... |
| CVE-2026-54753 | MEDIUM | 5.9 | — | Jun 26, 2026 | Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local H... |
| CVE-2026-48090 | MEDIUM | 5.9 | 0.6% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38... |
| CVE-2026-47205 | MEDIUM | 5.9 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5,... |
| CVE-2026-55448 | MEDIUM | 6.3 | — | Jun 26, 2026 | mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credent... |
| CVE-2026-54557 | MEDIUM | 5.5 | — | Jun 26, 2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its inst... |
| CVE-2026-47778 | MEDIUM | 4.4 | 0.2% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,... |
| CVE-2026-47775 | MEDIUM | 6.8 | 0.2% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,... |
| CVE-2026-47692 | MEDIUM | 4.3 | 0.2% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9... |
| CVE-2026-47207 | MEDIUM | 6.5 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9... |
| CVE-2026-56823 | MEDIUM | 5.4 | — | Jun 26, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-55686 | MEDIUM | 5.3 | — | Jun 26, 2026 | Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where... |
| CVE-2026-48529 | MEDIUM | 6 | — | Jun 26, 2026 | GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mo... |
| CVE-2026-45407 | MEDIUM | 5.5 | — | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch comm... |
| CVE-2026-28385 | MEDIUM | 5 | 0.2% | Jun 26, 2026 | In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import funct... |
| CVE-2026-13434 | MEDIUM | 4.9 | 0.2% | Jun 26, 2026 | A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now