2026 CVE Vulnerabilities

53,074 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-30237MEDIUM6.1Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a...
CVE-2026-27142MEDIUM6.1Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t...
CVE-2026-27138MEDIUM5.9Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the ...
CVE-2026-30835MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30233MEDIUM4.3OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization fl...
CVE-2026-30231MEDIUM5.3Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1....
CVE-2026-30228MEDIUM4.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30227MEDIUM5.3MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail ...
CVE-2026-30225MEDIUM4.3OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication c...
CVE-2026-30224MEDIUM5.4OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not r...
CVE-2026-29791MEDIUM6.5Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environmen...
CVE-2026-29790MEDIUM5.3dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.3...
CVE-2026-30847MEDIUM6.5Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publicatio...
CVE-2026-30843MEDIUM6.5Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Ref...
CVE-2026-3419MEDIUM5.3Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in ...
CVE-2026-30833MEDIUM5.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1...
CVE-2026-29110MEDIUM5.3Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator m...
CVE-2026-29082MEDIUM5.4Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview ren...
CVE-2026-27777MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-27027MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-26017MEDIUM6.3CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS acce...
CVE-2026-2752MEDIUM5.3Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send ...
CVE-2026-28106MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This ...
CVE-2026-28080MEDIUM4.3Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-1468MEDIUM5.1QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, w...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now