2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-31875MEDIUM5.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31868MEDIUM6.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31867MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (I...
CVE-2026-31863MEDIUM4.4Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca...
CVE-2026-31859MEDIUM6.1Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in...
CVE-2026-0231MEDIUM5.7An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obta...
CVE-2026-0230MEDIUM4A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator t...
CVE-2026-3429MEDIUM4.2A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to ...
CVE-2026-31853MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9...
CVE-2026-31813MEDIUM4.8Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been i...
CVE-2026-30236MEDIUM4.3OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and...
CVE-2026-30235MEDIUM6.5OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to ...
CVE-2026-20166MEDIUM5.4In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.1...
CVE-2026-20165MEDIUM6.5In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.251...
CVE-2026-20164MEDIUM6.5In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.251...
CVE-2026-20162MEDIUM6.3In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform versions below 10.2.2510...
CVE-2026-20118MEDIUM6.8A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software ...
CVE-2026-20117MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow ...
CVE-2026-20116MEDIUM6.1A vulnerability in the web-based management interface of  Cisco Finesse, Cisco Packaged Contact Center Enterprise (...
CVE-2026-1471MEDIUM6.5Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat...
CVE-2026-3848MEDIUM5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2026-30234MEDIUM6.5OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member w...
CVE-2026-29777MEDIUM6.5Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource...
CVE-2026-28803MEDIUM6.5Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner re...
CVE-2026-1732MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now