2026 CVE Vulnerabilities

45,094 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-52814MEDIUM5.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an una...
CVE-2026-52809MEDIUM6.8Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.Act...
CVE-2026-52807MEDIUM4.8Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go'...
CVE-2026-52804MEDIUM5.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their priv...
CVE-2026-52802MEDIUM5.4Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where att...
CVE-2026-52795MEDIUM4.3Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private reposi...
CVE-2026-50128MEDIUM5.3Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon...
CVE-2026-49278MEDIUM6.7Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ...
CVE-2026-47733MEDIUM4.4Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement comp...
CVE-2026-32315MEDIUM5.5motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Version...
CVE-2026-31978MEDIUM6.5motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection...
CVE-2026-13208MEDIUM6.5A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SE...
CVE-2026-48028MEDIUM6.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodo...
CVE-2026-46349MEDIUM5.3Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodo...
CVE-2026-53949MEDIUM5.3Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public ...
CVE-2026-53948MEDIUM5.4Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied C...
CVE-2026-53947MEDIUM5.3Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members sign...
CVE-2026-53946MEDIUM5.4Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch mis...
CVE-2026-53945MEDIUM4Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP reques...
CVE-2026-53944MEDIUM5.8Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible t...
CVE-2026-49220MEDIUM5.7Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which c...
CVE-2026-13034MEDIUM4.7Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had com...
CVE-2026-13030MEDIUM5.3Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potenti...
CVE-2026-13024MEDIUM4.2Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attac...
CVE-2026-13023MEDIUM5.3Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the rend...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now