2026 CVE Vulnerabilities

50,909 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-34985MEDIUM6.5LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-34837MEDIUM4.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_ass...
CVE-2026-34782MEDIUM4.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /ap...
CVE-2026-34722MEDIUM4.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for tick...
CVE-2026-34721MEDIUM6.5Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoin...
CVE-2026-34720MEDIUM4.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zamma...
CVE-2026-34719MEDIUM4.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was miss...
CVE-2026-34718MEDIUM6.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for tic...
CVE-2026-34248MEDIUM5.7Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (m...
CVE-2026-34166MEDIUM5.3LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter...
CVE-2026-30817MEDIUM5.7An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac...
CVE-2026-30816MEDIUM5.7An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated ad...
CVE-2026-20709MEDIUM6.6Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(...
CVE-2026-0814MEDIUM4.3The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2026-0811MEDIUM5.4The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-33459MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-32591MEDIUM5.5A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an u...
CVE-2026-33461MEDIUM6.5Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user w...
CVE-2026-33460MEDIUM4.3Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-12...
CVE-2026-2377MEDIUM6.5A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products all...
CVE-2026-39865MEDIUM5.9Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios ...
CVE-2026-39410MEDIUM4.8Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy be...
CVE-2026-39409MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() ...
CVE-2026-39407MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling ...
CVE-2026-39406MEDIUM5.3@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in ser...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now