2026 CVE Vulnerabilities

70,015 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28284HIGH8.8FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several aut...
CVE-2026-28210HIGH8.8FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnera...
CVE-2026-28209HIGH7.2FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, ...
CVE-2026-27944CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessibl...
CVE-2026-27723MEDIUM5.3OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker c...
CVE-2026-27023MEDIUM5Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request UR...
CVE-2026-26999HIGH7.5Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil...
CVE-2026-26998MEDIUM4.4Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil...
CVE-2026-26418HIGH7.5Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows rem...
CVE-2026-26417HIGH8.1A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Clie...
CVE-2026-26416HIGH8.8An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users t...
CVE-2026-26276MEDIUM5.4Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payloa...
CVE-2026-26196MEDIUM5.3Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik...
CVE-2026-26195MEDIUM6.1Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe tem...
CVE-2026-26194HIGH7.3Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting...
CVE-2026-26022MEDIUM5.4Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerabili...
CVE-2026-25921CRITICAL9.3Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos ...
CVE-2026-24457CRITICAL9.8An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbit...
CVE-2026-30798HIGH7.5Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-cl...
CVE-2026-30797HIGH8.1Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, An...
CVE-2026-30796HIGH7.5Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client R...
CVE-2026-30795HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Wind...
CVE-2026-30794——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-30793CRITICAL9.8Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Li...
CVE-2026-30792HIGH8.1A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (St...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now