2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3216MEDIUM5Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue a...
CVE-2026-3215MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Islandora a...
CVE-2026-3214MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.Thi...
CVE-2026-3213MEDIUM4.7Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam b...
CVE-2026-3212MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allo...
CVE-2026-3211MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Drupal Theme Negotiation by Rules allows Cross Site Request Forgery.T...
CVE-2026-3210MEDIUM5.3Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icon...
CVE-2026-2349MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Icons al...
CVE-2026-2348MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit ...
CVE-2026-26833CRITICAL9.8thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() fun...
CVE-2026-26832CRITICAL9.8node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, t...
CVE-2026-26831CRITICAL9.8textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When pr...
CVE-2026-24750MEDIUM5.4Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attac...
CVE-2026-20125HIGH7.7A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an aut...
CVE-2026-20115MEDIUM6.1A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confide...
CVE-2026-20114MEDIUM5.4A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, ...
CVE-2026-20113MEDIUM5.3A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software...
CVE-2026-20112MEDIUM4.8A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software...
CVE-2026-20110MEDIUM6.5A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of se...
CVE-2026-20108MEDIUM5.4A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, rem...
CVE-2026-20104MEDIUM6.1A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS93...
CVE-2026-20086HIGH8.6A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE...
CVE-2026-20084HIGH8.6A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to...
CVE-2026-20083MEDIUM6.5A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, ...
CVE-2026-20012HIGH8.6A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cis...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now