2026 CVE Vulnerabilities

65,619 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47679HIGH8.5GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user c...
CVE-2026-45801MEDIUM5.3GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user witho...
CVE-2026-100306MEDIUM5.3TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the...
CVE-2026-100305MEDIUM4.3TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /...
CVE-2026-100304MEDIUM5.3TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open wh...
CVE-2026-100303MEDIUM5.4TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes a...
CVE-2026-100192MEDIUM6.5X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint withou...
CVE-2026-97886MEDIUM6.3A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be...
CVE-2026-97885HIGH7.3A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affecte...
CVE-2026-97884MEDIUM6.3A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ...
CVE-2026-97883HIGH7.3A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db...
CVE-2026-97882HIGH7.3A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be...
CVE-2026-93366MEDIUM5.4Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author...
CVE-2026-91841HIGH7.8A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vul...
CVE-2026-91840HIGH7.8A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to r...
CVE-2026-91839HIGH7.8A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service im...
CVE-2026-91838HIGH7.8A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit t...
CVE-2026-84462HIGH8.6Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zamm...
CVE-2026-65828LOW2.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on At...
CVE-2026-61525HIGH8.8Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for ...
CVE-2026-56735MEDIUM5.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (H...
CVE-2026-56734MEDIUM5.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAu...
CVE-2026-56733HIGH8.7Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack...
CVE-2026-56732MEDIUM5.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanit...
CVE-2026-56731HIGH8.4Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user m...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now