2026 CVE Vulnerabilities

65,632 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-67226MEDIUM6.9RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-only atom exhaustion: ...
CVE-2026-67225MEDIUM6.3RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the stream protocol ...
CVE-2026-67223MEDIUM6.3RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance...
CVE-2026-67222MEDIUM5.9RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, mechanisms/1 applied...
CVE-2026-66078LOW2.1RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, protected tag b...
CVE-2026-66073MEDIUM6RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, Atom table exha...
CVE-2026-66071MEDIUM6RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom ...
CVE-2026-61837MEDIUM6.3RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQP 1.0 management GET...
CVE-2026-56729LOW2.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have dif...
CVE-2026-56724HIGH7.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission che...
CVE-2026-56723HIGH7.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a customer who can view a ticket can...
CVE-2026-18320MEDIUM6.1Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due ...
CVE-2026-18312MEDIUM6.1Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or...
CVE-2026-18311MEDIUM6.1Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its proces...
CVE-2026-100248HIGH8.4The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.
CVE-2026-100237MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun...
CVE-2026-97869MEDIUM4.1A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the fun...
CVE-2026-97868LOW3.5A security vulnerability has been detected in sheshbabu zen up to 1.5.0. Affected by this issue is the function dangerou...
CVE-2026-97469MEDIUM4.3PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() ...
CVE-2026-96874LOW2.3Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Ca...
CVE-2026-92161CRITICAL9.8FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7...
CVE-2026-85293MEDIUM4.8InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-bet...
CVE-2026-85292MEDIUM4.8InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-85291MEDIUM6.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-85290MEDIUM5.3InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now