2026 CVE Vulnerabilities

52,241 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-30231MEDIUM5.3Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1....
CVE-2026-30228MEDIUM4.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30227MEDIUM5.3MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail ...
CVE-2026-30225MEDIUM4.3OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication c...
CVE-2026-30224MEDIUM5.4OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not r...
CVE-2026-29791MEDIUM6.5Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environmen...
CVE-2026-29790MEDIUM5.3dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.3...
CVE-2026-30847MEDIUM6.5Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publicatio...
CVE-2026-30843MEDIUM6.5Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Ref...
CVE-2026-3419MEDIUM5.3Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in ...
CVE-2026-30833MEDIUM5.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1...
CVE-2026-29110MEDIUM5.3Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator m...
CVE-2026-29082MEDIUM5.4Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview ren...
CVE-2026-27777MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-27027MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-26017MEDIUM6.3CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS acce...
CVE-2026-2752MEDIUM5.3Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send ...
CVE-2026-28106MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This ...
CVE-2026-28080MEDIUM4.3Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-1468MEDIUM5.1QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, w...
CVE-2026-2830MEDIUM6.1The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflect...
CVE-2026-29183MEDIUM6.1SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability...
CVE-2026-29049MEDIUM4.3melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cach...
CVE-2026-29048MEDIUM6.1HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identifi...
CVE-2026-29038MEDIUM6.1changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now