2026 CVE Vulnerabilities

65,524 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100699MEDIUM5.3Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser)...
CVE-2026-100698MEDIUM5.8Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/f...
CVE-2026-100697HIGH8.6Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6....
CVE-2026-100696MEDIUM5.8Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the option...
CVE-2026-100695MEDIUM6.1Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpol...
CVE-2026-100694MEDIUM6.1Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media t...
CVE-2026-100693HIGH8.4Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-litera...
CVE-2026-100692HIGH7.5Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopp...
CVE-2026-100691MEDIUM5.4Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does no...
CVE-2026-100690HIGH7.5Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.j...
CVE-2026-100689MEDIUM5.9GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodu...
CVE-2026-100688MEDIUM6.5Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/...
CVE-2026-100687MEDIUM5.5Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table update...
CVE-2026-100686HIGH8.1Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endp...
CVE-2026-100685HIGH7.7Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enume...
CVE-2026-100684HIGH8.1Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. ...
CVE-2026-100683HIGH8Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlT...
CVE-2026-100682HIGH8.8Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extrac...
CVE-2026-100681MEDIUM5.4Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability...
CVE-2026-100680HIGH8.1Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validat...
CVE-2026-100679HIGH8.8stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypas...
CVE-2026-100678MEDIUM6.5stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who kn...
CVE-2026-100677MEDIUM5.3stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file loc...
CVE-2026-100676HIGH8.2January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG...
CVE-2026-100675MEDIUM6.5stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now