2026 CVE Vulnerabilities

50,812 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7326HIGH7.5A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows ...
CVE-2026-70606MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6...
CVE-2026-70605MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70604HIGH7.4Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10...
CVE-2026-70603MEDIUM6Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6,...
CVE-2026-70602MEDIUM6.6Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70601HIGH7.5Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,...
CVE-2026-70600LOW3.1Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70599MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,...
CVE-2026-70598LOW3.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10...
CVE-2026-70597MEDIUM6.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70596MEDIUM4.3Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user ...
CVE-2026-70595MEDIUM4Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, s...
CVE-2026-60053CRITICAL9.1Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Admin...
CVE-2026-60023HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An...
CVE-2026-53992MEDIUM6.1ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remot...
CVE-2026-50749MEDIUM6.5Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica...
CVE-2026-49331MEDIUM6.5A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for...
CVE-2026-48912MEDIUM6.5Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ...
CVE-2026-48911HIGH7.5Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: throug...
CVE-2026-48834HIGH7.5Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: t...
CVE-2026-39924MEDIUM6.8Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess...
CVE-2026-39923CRITICAL9.2Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers t...
CVE-2026-32835Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18531MEDIUM5.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now