2026 CVE Vulnerabilities

53,091 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-28447MEDIUM6.5OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that ...
CVE-2026-28394MEDIUM6.9OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attacke...
CVE-2026-28492MEDIUM6.5File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2026-28413MEDIUM6.1Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a ...
CVE-2026-28405MEDIUM5.4MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.1, the courses/<...
CVE-2026-22723MEDIUM6.5Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry...
CVE-2026-28350MEDIUM6.1lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, th...
CVE-2026-28348MEDIUM6.1lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, th...
CVE-2026-28343MEDIUM6.1CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to ver...
CVE-2026-28223MEDIUM6.1Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a...
CVE-2026-28222MEDIUM6.1Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a...
CVE-2026-21621MEDIUM5.3Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privile...
CVE-2026-27723MEDIUM5.3OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker c...
CVE-2026-27023MEDIUM5Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request UR...
CVE-2026-26998MEDIUM4.4Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil...
CVE-2026-26276MEDIUM5.4Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payloa...
CVE-2026-26196MEDIUM5.3Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik...
CVE-2026-26195MEDIUM6.1Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe tem...
CVE-2026-26022MEDIUM5.4Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerabili...
CVE-2026-30785MEDIUM5.5Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins...
CVE-2026-26377MEDIUM5.4Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the N...
CVE-2026-3236MEDIUM4.3In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting i...
CVE-2026-28551MEDIUM4.7Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerabi...
CVE-2026-28549MEDIUM4.7Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability...
CVE-2026-28548MEDIUM5.5Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability m...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now