2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-77522MEDIUM4.3MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document impor...
CVE-2026-77520MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can ...
CVE-2026-77519MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path lo...
CVE-2026-77518MEDIUM5MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows anothe...
CVE-2026-77517MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph opera...
CVE-2026-77516MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member de...
CVE-2026-73551MEDIUM5.3Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73511MEDIUM5.3Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-59816MEDIUM4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7...
CVE-2026-58272MEDIUM5.3Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1...
CVE-2026-58270MEDIUM6.5Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,...
CVE-2026-55179MEDIUM6.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2...
CVE-2026-79320MEDIUM6.1Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downs...
CVE-2026-79319MEDIUM5.3Stencil core 4.43.5 is vulnerable to Incorrect Access Control.
CVE-2026-79318MEDIUM6.5web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file(...
CVE-2026-73549MEDIUM5.3Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-62247MEDIUM6.5Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authoriz...
CVE-2026-58271MEDIUM6.8Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,...
CVE-2026-54915MEDIUM5.4Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /aut...
CVE-2026-50572MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-49995MEDIUM4.8Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron fiel...
CVE-2026-48521MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-45381MEDIUM5.1Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint ins...
CVE-2026-94494MEDIUM5jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenant...
CVE-2026-94414MEDIUM5.4jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authent...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now