2026 CVE Vulnerabilities

70,015 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28492MEDIUM6.5File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2026-28443CRITICAL9.8OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint h...
CVE-2026-28442HIGH8.5ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, u...
CVE-2026-28436HIGH7.2Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted ...
CVE-2026-28413MEDIUM6.1Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a ...
CVE-2026-28410HIGH8.1The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to ve...
CVE-2026-28405MEDIUM5.4MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.1, the courses/<...
CVE-2026-22723MEDIUM6.5Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry...
CVE-2026-0848CRITICAL10NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegment...
CVE-2026-28790HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an ...
CVE-2026-28789HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated ...
CVE-2026-28353CRITICAL10Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1....
CVE-2026-28350MEDIUM6.1lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, th...
CVE-2026-28348MEDIUM6.1lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, th...
CVE-2026-28343MEDIUM6.1CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to ver...
CVE-2026-28342HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash AP...
CVE-2026-28277HIGH7.2LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ...
CVE-2026-28223MEDIUM6.1Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a...
CVE-2026-28222MEDIUM6.1Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a...
CVE-2026-21621MEDIUM5.3Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privile...
CVE-2026-3459HIGH8.1The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due...
CVE-2026-3047HIGH8.8A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is config...
CVE-2026-3009HIGH8.1A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an...
CVE-2026-29054HIGH7.5Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, ther...
CVE-2026-28287HIGH8.8FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now