2026 CVE Vulnerabilities

70,494 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28276HIGH7.5Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions p...
CVE-2026-28275HIGH8.1Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate p...
CVE-2026-28274HIGH8.7Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to S...
CVE-2026-28269HIGH8.8Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functio...
CVE-2026-28230MEDIUM6.3SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger se...
CVE-2026-28226MEDIUM6.5Phishing Club is a phishing simulation and man-in-the-middle framework. Prior to version 1.30.2, an authenticated SQL in...
CVE-2026-28225MEDIUM6.5Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ...
CVE-2026-28217MEDIUM6.5hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query ac...
CVE-2026-28216HIGH8.3hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify o...
CVE-2026-28215CRITICAL9.1hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overw...
CVE-2026-28213CRITICAL9.8EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password"...
CVE-2026-28211HIGH7.8The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability ...
CVE-2026-28208MEDIUM5.9Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `...
CVE-2026-28207HIGH7.3Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command inj...
CVE-2026-27839MEDIUM4.3wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values`...
CVE-2026-27838LOW3.5wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calli...
CVE-2026-27638HIGH7.1Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoi...
CVE-2026-3263HIGH8.8A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this...
CVE-2026-3262HIGH8.8A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is...
CVE-2026-3261CRITICAL9.8A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settin...
CVE-2026-28227LOW2.7Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publ...
CVE-2026-28219MEDIUM4.3Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper author...
CVE-2026-28218MEDIUM5.4Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access c...
CVE-2026-27835MEDIUM4.3wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet`...
CVE-2026-27457MEDIUM4.3Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now