2026 CVE Vulnerabilities

47,994 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-45543MEDIUM5.3Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collab...
CVE-2026-45286MEDIUM4.3Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6...
CVE-2026-45285MEDIUM6.4Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before ...
CVE-2026-45283MEDIUM4.3Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, a...
CVE-2026-45282MEDIUM6.5Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a...
CVE-2026-45279MEDIUM6.5Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, ...
CVE-2026-45278MEDIUM6.1Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can ...
CVE-2026-45275MEDIUM6.5Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability...
CVE-2026-40990MEDIUM6.5OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Produc...
CVE-2026-40989MEDIUM6.5Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versi...
CVE-2026-23638MEDIUM6.5Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil...
CVE-2026-10283MEDIUM6.3A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setti...
CVE-2026-10282MEDIUM5.3A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the fi...
CVE-2026-10279MEDIUM6.3A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the ...
CVE-2026-10278MEDIUM6.3A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index....
CVE-2026-10277MEDIUM6.3A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affect...
CVE-2026-10276MEDIUM6.3A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of t...
CVE-2026-8643MEDIUM5.5pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute ...
CVE-2026-45701MEDIUM6.9Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6,...
CVE-2026-45267MEDIUM6.5Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed ...
CVE-2026-45264MEDIUM4.3Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18....
CVE-2026-45157MEDIUM6.3Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a...
CVE-2026-45153MEDIUM4.6Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlockin...
CVE-2026-44740MEDIUM6.5Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may ...
CVE-2026-42679MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classifie...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now