2026 CVE Vulnerabilities

51,094 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-21790MEDIUM6.3HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to byp...
CVE-2026-33353MEDIUM6.5Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authoriza...
CVE-2026-33349MEDIUM5.9fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0....
CVE-2026-33347MEDIUM6.1league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in th...
CVE-2026-33345MEDIUM6.5solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organiza...
CVE-2026-33331MEDIUM5.4oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1....
CVE-2026-33326MEDIUM4.3Keystone is a content management system for Node.js. Prior to version 6.5.2, {field}.isFilterable access control can be ...
CVE-2026-33314MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoof...
CVE-2026-21783MEDIUM4.3HCL Traveler is affected by sensitive information disclosure.  The application generates some error messages that provid...
CVE-2026-33769MEDIUM5.3Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path...
CVE-2026-33627MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33527MEDIUM4.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33429MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33421MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33323MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-23924MEDIUM6.1Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to t...
CVE-2026-23923MEDIUM6.9An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The...
CVE-2026-33401MEDIUM6.5Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in c...
CVE-2026-33400MEDIUM5.4Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scrip...
CVE-2026-33162MEDIUM6.5Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control pa...
CVE-2026-33161MEDIUM4.3Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R...
CVE-2026-33160MEDIUM5.3Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R...
CVE-2026-33159MEDIUM6.5Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R...
CVE-2026-33158MEDIUM6.5Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R...
CVE-2026-33700MEDIUM4.9Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:pr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now