2026 CVE Vulnerabilities

67,127 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33670HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to tr...
CVE-2026-33669HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/...
CVE-2026-33664MEDIUM5.4Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied fl...
CVE-2026-33661HIGH7.5Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `...
CVE-2026-33658MEDIUM6.5Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a...
CVE-2026-33653MEDIUM5.4Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exis...
CVE-2026-28377HIGH7.5A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, p...
CVE-2026-1556MEDIUM6.5Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 ...
CVE-2026-0748MEDIUM4.3In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" ...
CVE-2026-4933HIGH7.5Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects...
CVE-2026-4393MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allows Cross Site Request Forgery.This issue ...
CVE-2026-3622HIGH7.5The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-boun...
CVE-2026-3573HIGH7.5Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affect...
CVE-2026-3532MEDIUM4.2Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation....
CVE-2026-3531MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Au...
CVE-2026-3530MEDIUM4.3Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forg...
CVE-2026-3529MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Google Anal...
CVE-2026-3528MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation...
CVE-2026-3527MEDIUM6.5Missing Authentication for Critical Function vulnerability in Drupal AJAX Dashboard allows Exploiting Incorrectly Config...
CVE-2026-3526MEDIUM5.3Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects...
CVE-2026-3525MEDIUM5.3Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects...
CVE-2026-33742MEDIUM5.4Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fiel...
CVE-2026-33738MEDIUM5.4Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored wit...
CVE-2026-33645HIGH8.1Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerabilit...
CVE-2026-33644MEDIUM4.3Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the SSRF protection in `PhotoUrlRule.php` c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now