2026 CVE Vulnerabilities

65,619 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56730LOW2.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerabilit...
CVE-2026-56728MEDIUM5.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a broken access control vulnerabilit...
CVE-2026-56727HIGH7.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary In Zammad's inbound PGP emai...
CVE-2026-56726MEDIUM5.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, this vulnerability breaks normal tic...
CVE-2026-56725HIGH8.7Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An unauthenticated request t...
CVE-2026-97879MEDIUM5.3A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function ...
CVE-2026-97878HIGH7.3A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /d...
CVE-2026-97877HIGH7.3A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService....
CVE-2026-97871HIGH7.3A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of ...
CVE-2026-95835MEDIUM5.6Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other th...
CVE-2026-95834MEDIUM4.6Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program...
CVE-2026-94445HIGH8.8A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's truste...
CVE-2026-93365MEDIUM6.5Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Aut...
CVE-2026-93364MEDIUM4.3Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role ...
CVE-2026-93363MEDIUM4.3The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that a...
CVE-2026-91837HIGH7.8A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can explo...
CVE-2026-89032HIGH7.7BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that al...
CVE-2026-80432MEDIUM6Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows ...
CVE-2026-67421MEDIUM4.5RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Man...
CVE-2026-67420LOW2.3RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ OAu...
CVE-2026-67419HIGH7.1RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exch...
CVE-2026-67415MEDIUM5.9RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, the Shovel parameter parser converted at...
CVE-2026-67413MEDIUM6RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the optional rabbitmq_j...
CVE-2026-67412MEDIUM6RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation u...
CVE-2026-67411MEDIUM6RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now