2026 CVE Vulnerabilities

52,116 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-0835MEDIUM5.4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2026-2581MEDIUM5.9This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulne...
CVE-2026-1527MEDIUM4.6ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject...
CVE-2026-32269MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32259MEDIUM6.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9...
CVE-2026-32251MEDIUM6.5Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resourc...
CVE-2026-32249MEDIUM5.5Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encoun...
CVE-2026-32240MEDIUM6.5Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: ...
CVE-2026-32239MEDIUM6.5Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length valu...
CVE-2026-32245MEDIUM6.5Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the...
CVE-2026-32237MEDIUM6.5Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to ex...
CVE-2026-32235MEDIUM4.7Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backs...
CVE-2026-32230MEDIUM5.3Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration?...
CVE-2026-32142MEDIUM5.3Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is...
CVE-2026-2376MEDIUM5.4A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal ...
CVE-2026-32139MEDIUM5.4Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload...
CVE-2026-32100MEDIUM5.3Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vul...
CVE-2026-31890MEDIUM5.5Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li...
CVE-2026-31873MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses Strin...
CVE-2026-31860MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML ...
CVE-2026-31841MEDIUM6.5Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0...
CVE-2026-29066MEDIUM6.2Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs....
CVE-2026-24125MEDIUM6.3Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content...
CVE-2026-21670MEDIUM6.5A vulnerability allowing a low-privileged user to extract saved SSH credentials.
CVE-2026-21668MEDIUM6.5A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now