2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-63342MEDIUM6.3Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ap...
CVE-2026-61681MEDIUM4.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, th...
CVE-2026-36472MEDIUM5.2CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allow...
CVE-2026-36471MEDIUM5.8Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote att...
CVE-2026-36470MEDIUM5.8CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied i...
CVE-2026-36468MEDIUM6.1Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitra...
CVE-2026-93339MEDIUM5.4Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that all...
CVE-2026-82355MEDIUM4.2When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airf...
CVE-2026-75158MEDIUM4.3Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting ...
CVE-2026-61630MEDIUM4.2nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enable...
CVE-2026-55625MEDIUM4.9GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/adm...
CVE-2026-54584MEDIUM5.3mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including w...
CVE-2026-52743MEDIUM4.3GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a ...
CVE-2026-52742MEDIUM5.1GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical...
CVE-2026-52740MEDIUM5.3GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names ca...
CVE-2026-94394MEDIUM6.3When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall ...
CVE-2026-94393MEDIUM6.4When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without prope...
CVE-2026-94387MEDIUM5.4Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_v...
CVE-2026-94382MEDIUM4.2Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-...
CVE-2026-94379MEDIUM6.9The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-cr...
CVE-2026-94373MEDIUM6.3MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The Cont...
CVE-2026-94372MEDIUM6.3MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP ...
CVE-2026-94216MEDIUM4.3A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This...
CVE-2026-94214MEDIUM4.3A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affe...
CVE-2026-91867MEDIUM4.3When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server tha...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now