2026 CVE Vulnerabilities

70,496 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27835MEDIUM4.3wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet`...
CVE-2026-27457MEDIUM4.3Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`...
CVE-2026-27449HIGH7.5Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versi...
CVE-2026-27154MEDIUM6.1Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, a user full name c...
CVE-2026-27153LOW2.7Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, moderators could e...
CVE-2026-25741HIGH7.1Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpo...
CVE-2026-27162MEDIUM4.9Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `posts_nearby` was...
CVE-2026-27152LOW3.8Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-p...
CVE-2026-27151LOW2.7Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the `move_posts` a...
CVE-2026-27150LOW3.8Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_...
CVE-2026-27149MEDIUM6.5Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, SQL injection in P...
CVE-2026-27021MEDIUM5.3Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoin...
CVE-2026-22207CRITICAL9.8OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows u...
CVE-2026-22206HIGH8.8SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to exe...
CVE-2026-22205HIGH8.7SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows una...
CVE-2026-27510HIGH8.8Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.dogg...
CVE-2026-27509HIGH8.5Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorizat...
CVE-2026-27141HIGH7.5Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic
CVE-2026-26979LOW2.7Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users are able...
CVE-2026-26973MEDIUM4.3Discourse is an open source discussion platform. Versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 have an IDOR (Insec...
CVE-2026-23939HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elix...
CVE-2026-1565HIGH8.8The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-1241HIGH8.7The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web manage...
CVE-2026-26938HIGH7.7Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which cou...
CVE-2026-26937HIGH7.5Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Dat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now