2026 CVE Vulnerabilities

68,146 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4366MEDIUM5.8A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect...
CVE-2026-33189——Rejected reason: Further research determined the issue originates from a different product.
CVE-2026-33188——Rejected reason: Further research determined the issue originates from a different product.
CVE-2026-33187——Rejected reason: Further research determined the issue originates from a different product.
CVE-2026-33058MEDIUM6.5Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ...
CVE-2026-32266LOW2.4The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on ...
CVE-2026-32265MEDIUM6.9The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una...
CVE-2026-32256HIGH7.5music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF pars...
CVE-2026-32254HIGH7.1Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not...
CVE-2026-31938MEDIUM6.1jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the...
CVE-2026-31898MEDIUM6.5jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot...
CVE-2026-31891MEDIUM6.5Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc...
CVE-2026-31865MEDIUM5.3Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun...
CVE-2026-30922HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service ...
CVE-2026-30884CRITICAL9.6mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customi...
CVE-2026-2575MEDIUM5.3A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS...
CVE-2026-29112HIGH7.5DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dic...
CVE-2026-1926MEDIUM5.3The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2026-1780MEDIUM6.1The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v...
CVE-2026-4356LOW2.4A flaw has been found in itsourcecode University Management System 1.0. Affected is an unknown function of the file /add...
CVE-2026-4268MEDIUM6.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgm...
CVE-2026-2603HIGH8.1A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an ...
CVE-2026-2092HIGH7.7A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val...
CVE-2026-29056HIGH8.8Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat...
CVE-2026-28500CRITICAL9.1Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now