2026 CVE Vulnerabilities

48,325 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-40094MEDIUM4.3nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network...
CVE-2026-39960MEDIUM5.4Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that cause...
CVE-2026-9136MEDIUM6.5A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlle...
CVE-2026-9124MEDIUM5.3Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacke...
CVE-2026-9122MEDIUM6.5Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentiall...
CVE-2026-9116MEDIUM4.3Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker t...
CVE-2026-9115MEDIUM4.3Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker ...
CVE-2026-9113MEDIUM4.3Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of...
CVE-2026-9110MEDIUM4.2Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had...
CVE-2026-47099MEDIUM6.1TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows atta...
CVE-2026-39311MEDIUM6.8Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-35016MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authen...
CVE-2026-35015MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows ...
CVE-2026-35014MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows aut...
CVE-2026-35013MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows a...
CVE-2026-35012MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows a...
CVE-2026-35011MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authent...
CVE-2026-35010MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows au...
CVE-2026-35009MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows auth...
CVE-2026-35008MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authen...
CVE-2026-35007MEDIUM5.1Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows a...
CVE-2026-2813MEDIUM4.1ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could e...
CVE-2026-2812MEDIUM5.3ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthent...
CVE-2026-26028MEDIUM6.1CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Dif...
CVE-2026-30691MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitra...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now