2026 CVE Vulnerabilities

65,619 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100380MEDIUM5.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-100379MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App a...
CVE-2026-100378MEDIUM5.3Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionali...
CVE-2026-100377MEDIUM6.9Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda ...
CVE-2026-100376MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-100369HIGH8.4CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs...
CVE-2026-96878MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ...
CVE-2026-96877MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ...
CVE-2026-96876MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ...
CVE-2026-96875MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ...
CVE-2026-93682MEDIUM5.8When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redi...
CVE-2026-5267HIGH7.5Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API tha...
CVE-2026-57861——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53990——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-100373MEDIUM4.1OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function...
CVE-2026-100372HIGH7.2ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authent...
CVE-2026-100368HIGH8.4CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide spe...
CVE-2026-100310HIGH7GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environmen...
CVE-2026-100208HIGH7.5Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a networ...
CVE-2026-97897LOW3.5A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the...
CVE-2026-97896LOW3.5A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationF...
CVE-2026-97895MEDIUM6.3A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webk...
CVE-2026-97064CRITICAL9.1X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the d...
CVE-2026-97063CRITICAL9.1X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobi...
CVE-2026-97060HIGH7.2X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to m...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now