2026 CVE Vulnerabilities

65,632 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-85289MEDIUM6.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-85274MEDIUM6.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-67236HIGH8.2RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_autho...
CVE-2026-62262CRITICAL9.1Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is ...
CVE-2026-54790MEDIUM6InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-50547HIGH7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-49850HIGH7.5InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-44642HIGH8.1Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_right...
CVE-2026-42324HIGH7.2Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.ph...
CVE-2026-42323HIGH7.2Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php ac...
CVE-2026-42322CRITICAL9.1Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_page...
CVE-2026-39372MEDIUM4.9InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-39353CRITICAL9.1InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1,...
CVE-2026-33639HIGH7.2InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo...
CVE-2026-100230MEDIUM5.3Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, m...
CVE-2026-97866MEDIUM5.6A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of t...
CVE-2026-96812HIGH8.8Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73c...
CVE-2026-93306HIGH7.1IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 ...
CVE-2026-93030MEDIUM6.5FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity in...
CVE-2026-88389MEDIUM6.2Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Cr...
CVE-2026-84882HIGH7.5IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload compon...
CVE-2026-84862HIGH7.2IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticat...
CVE-2026-60101——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-60100——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-60099——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now