2026 CVE Vulnerabilities

51,094 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-33680MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` meth...
CVE-2026-33677MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:proje...
CVE-2026-33676MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tas...
CVE-2026-33675MEDIUM5.4Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the migration helper functions `...
CVE-2026-33474MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Starting in version 1.0.0-rc0 and prior to version 2.2.0...
CVE-2026-33473MEDIUM5.7Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any...
CVE-2026-29840MEDIUM5.4JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app...
CVE-2026-33315MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, the Caldav endpoint allows login...
CVE-2026-33313MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, an authenticated user can read a...
CVE-2026-30662MEDIUM6.5ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method...
CVE-2026-30661MEDIUM6.1iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within th...
CVE-2026-30655MEDIUM6.5SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remote atta...
CVE-2026-28755MEDIUM5.4NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling o...
CVE-2026-28753MEDIUM6.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of...
CVE-2026-33311MEDIUM4.7DiceBear is an avatar library for designers and developers. Starting in version 5.0.0 and prior to versions 5.4.4, 6.1.4...
CVE-2026-4728MEDIUM6.5Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
CVE-2026-4649MEDIUM5.3Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exch...
CVE-2026-32642MEDIUM4.3Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application us...
CVE-2026-4754MEDIUM6.1CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.
CVE-2026-4752MEDIUM6.4Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329.
CVE-2026-4751MEDIUM5.3NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0.
CVE-2026-4749MEDIUM6.5NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0.
CVE-2026-3138MEDIUM6.5The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing ...
CVE-2026-4743MEDIUM5.2NULL Pointer Dereference vulnerability in taurusxin ncmdump (‎src/utils‎ modules). This vulnerability is associated with...
CVE-2026-4733MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affect...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now