2026 CVE Vulnerabilities

53,206 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66029MEDIUM5.4Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent...
CVE-2026-66028HIGH7.1Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authe...
CVE-2026-64645MEDIUM6.1Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64644MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64643MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64642HIGH8.2Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted reque...
CVE-2026-64641HIGH7.5Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-59239HIGH8.6Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authe...
CVE-2026-55579CRITICAL9.8Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor s...
CVE-2026-55578HIGH8.8Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the termin...
CVE-2026-54540HIGH8.8Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated term...
CVE-2026-54272MEDIUM6.9ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2...
CVE-2026-51235Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-48052MEDIUM5.4Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i...
CVE-2026-48051LOW3.5Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery sy...
CVE-2026-48030CRITICAL9.9Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Comm...
CVE-2026-45623CRITICAL9.1PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ...
CVE-2026-17570MEDIUM4.3Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg...
CVE-2026-17569MEDIUM4.3Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per...
CVE-2026-17568HIGH8.8Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm...
CVE-2026-17552CRITICAL9.1Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concaten...
CVE-2026-66731HIGH8.7facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser...
CVE-2026-66730HIGH8.7facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau...
CVE-2026-66729HIGH8.7facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows u...
CVE-2026-66391MEDIUM6.5Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Ap...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now