2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-35515MEDIUM6.1Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() int...
CVE-2026-35492MEDIUM6.5Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vul...
CVE-2026-35491MEDIUM6.1FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35487MEDIUM5.3text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate...
CVE-2026-1079MEDIUM6A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Auto...
CVE-2026-5384MEDIUM5.8An issue that could allow a credential to be updated and used for a task from outside of the authorized organization sco...
CVE-2026-5383MEDIUM4.4An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved....
CVE-2026-5380MEDIUM5.3An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields ...
CVE-2026-5378MEDIUM6.8An issue that allowed administrators to create and update users outside of their authorized organization scope has been ...
CVE-2026-5376MEDIUM5.9An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolve...
CVE-2026-5374MEDIUM5.8An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization...
CVE-2026-5372MEDIUM6.4An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This ...
CVE-2026-35484MEDIUM5.3text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate...
CVE-2026-35483MEDIUM5.3text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate...
CVE-2026-35480MEDIUM6.2go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec ...
CVE-2026-35462MEDIUM4.3Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are...
CVE-2026-35461MEDIUM4.3Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows aut...
CVE-2026-35460MEDIUM5.4Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Pa...
CVE-2026-33033MEDIUM6.5An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote a...
CVE-2026-3466MEDIUM5.4Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkm...
CVE-2026-33866MEDIUM4.3MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due ...
CVE-2026-33865MEDIUM5.4MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in it...
CVE-2026-4420MEDIUM5.4Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker ...
CVE-2026-34903MEDIUM5.4Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2026-34899MEDIUM5.3Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now