2026 CVE Vulnerabilities

51,177 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-32844MEDIUM6.1XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method....
CVE-2026-32303MEDIUM5.9Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerabilit...
CVE-2026-30580MEDIUM4.3File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" func...
CVE-2026-30579MEDIUM6.5File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" function...
CVE-2026-30578MEDIUM6.5File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of th...
CVE-2026-29828MEDIUM6.1DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field proj...
CVE-2026-22902MEDIUM6.7A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator ac...
CVE-2026-22895MEDIUM4.8A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an admi...
CVE-2026-32986MEDIUM6.1Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject...
CVE-2026-33312MEDIUM5.4Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, t...
CVE-2026-29794MEDIUM5.3Vikunja is an open-source self-hosted task management platform. Starting in version 0.8 and prior to version 2.2.0, unau...
CVE-2026-4485MEDIUM6.3A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown functio...
CVE-2026-33372MEDIUM5.4An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability e...
CVE-2026-33371MEDIUM4.3An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists i...
CVE-2026-33370MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability e...
CVE-2026-33369MEDIUM4.3Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a F...
CVE-2026-33368MEDIUM6.1Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Clas...
CVE-2026-31382MEDIUM6.1The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-s...
CVE-2026-31381MEDIUM5.3An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callb...
CVE-2026-33136MEDIUM6.1WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)...
CVE-2026-33135MEDIUM6.1WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)...
CVE-2026-33132MEDIUM5.3ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users t...
CVE-2026-32305MEDIUM5.3Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea...
CVE-2026-25792MEDIUM6.5Greenshot is an open source Windows screenshot utility. Versions 1.3.312 and below have untrusted executable search path...
CVE-2026-33130MEDIUM6.5Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now