2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-64684MEDIUM6.8RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransp...
CVE-2026-61597MEDIUM5.1djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-92814MEDIUM4.2changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary marku...
CVE-2026-92813MEDIUM4.9Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing una...
CVE-2026-92812MEDIUM6.8decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix ...
CVE-2026-92811MEDIUM6.5browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints,...
CVE-2026-92810MEDIUM4.3PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allo...
CVE-2026-92809MEDIUM4.3PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authentica...
CVE-2026-92803MEDIUM5.3LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated acc...
CVE-2026-92802MEDIUM4.3kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing ...
CVE-2026-92800MEDIUM6.8Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent document...
CVE-2026-92795MEDIUM6.5Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticate...
CVE-2026-92790MEDIUM6.5Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper t...
CVE-2026-92789MEDIUM6.5Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after...
CVE-2026-92781MEDIUM6.3Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten he...
CVE-2026-92778MEDIUM5.4CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers...
CVE-2026-92775MEDIUM6.5Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches...
CVE-2026-92774MEDIUM4.3Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based acce...
CVE-2026-92771MEDIUM6.5Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing ...
CVE-2026-92770MEDIUM6.5Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credenti...
CVE-2026-92765MEDIUM6.5ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticate...
CVE-2026-92764MEDIUM4.3OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, ...
CVE-2026-92760MEDIUM6.5Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restr...
CVE-2026-92759MEDIUM6.5SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that...
CVE-2026-92754MEDIUM4.3PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now