2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-3848MEDIUM5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2026-30234MEDIUM6.5OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member w...
CVE-2026-29777MEDIUM6.5Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource...
CVE-2026-28803MEDIUM6.5Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner re...
CVE-2026-1732MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2026-1663MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2026-1230MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18...
CVE-2026-1090MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2026-0602MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 1...
CVE-2026-32229MEDIUM6.8In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled
CVE-2026-3904MEDIUM6.2Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library ...
CVE-2026-32061MEDIUM6.7OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that al...
CVE-2026-3784MEDIUM6.5curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses diffe...
CVE-2026-3783MEDIUM5.3When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl...
CVE-2026-1965MEDIUM6.5libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS r...
CVE-2026-3906MEDIUM4.3WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collab...
CVE-2026-3492MEDIUM6.4The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including...
CVE-2026-3903MEDIUM4.3The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Cross-Site Request F...
CVE-2026-2918MEDIUM6.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...
CVE-2026-2917MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...
CVE-2026-3825MEDIUM6.1IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attacker...
CVE-2026-3824MEDIUM6.1IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL...
CVE-2026-3534MEDIUM6.4The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-c...
CVE-2026-3884MEDIUM6.1Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that a...
CVE-2026-2707MEDIUM6.4The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now