2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-94533MEDIUM6.5lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticat...
CVE-2026-94532MEDIUM6.5lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows aut...
CVE-2026-93340MEDIUM6.8Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote ...
CVE-2026-88756MEDIUM5.3Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitte...
CVE-2026-78806MEDIUM5.5An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker t...
CVE-2026-61852MEDIUM5.8Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-61851MEDIUM6.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-61743MEDIUM6.3Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-61541MEDIUM6.9Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests co...
CVE-2026-59830MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-cont...
CVE-2026-59815MEDIUM4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7...
CVE-2026-46650MEDIUM4.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2...
CVE-2026-17054MEDIUM5.3The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-process...
CVE-2026-15890MEDIUM5.3The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead...
CVE-2026-94588MEDIUM4.4In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is...
CVE-2026-93433MEDIUM5.5A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specia...
CVE-2026-88745MEDIUM6.1EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.
CVE-2026-88412MEDIUM5.3An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows...
CVE-2026-88408MEDIUM6.5FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/...
CVE-2026-88403MEDIUM6.5A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to...
CVE-2026-79919MEDIUM6.3MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under th...
CVE-2026-79918MEDIUM6.3MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox ho...
CVE-2026-79917MEDIUM6.5MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{...
CVE-2026-79317MEDIUM4.8A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and aut...
CVE-2026-77525MEDIUM4.2MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now