2026 CVE Vulnerabilities

53,108 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-26276MEDIUM5.4Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payloa...
CVE-2026-26196MEDIUM5.3Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik...
CVE-2026-26195MEDIUM6.1Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe tem...
CVE-2026-26022MEDIUM5.4Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerabili...
CVE-2026-30785MEDIUM5.5Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins...
CVE-2026-26377MEDIUM5.4Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the N...
CVE-2026-3236MEDIUM4.3In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting i...
CVE-2026-28551MEDIUM4.7Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerabi...
CVE-2026-28549MEDIUM4.7Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability...
CVE-2026-28548MEDIUM5.5Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability m...
CVE-2026-28547MEDIUM5.5Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerabil...
CVE-2026-28546MEDIUM5.5Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect a...
CVE-2026-28542MEDIUM5.5Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability m...
CVE-2026-2893MEDIUM6.5The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_...
CVE-2026-28550MEDIUM4.7Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may a...
CVE-2026-28545MEDIUM4.7Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av...
CVE-2026-28544MEDIUM4.7Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av...
CVE-2026-28543MEDIUM4.7Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerab...
CVE-2026-28541MEDIUM5.5Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may ...
CVE-2026-28539MEDIUM5.5Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerabilit...
CVE-2026-28538MEDIUM5.5Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability...
CVE-2026-28537MEDIUM5.5Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availab...
CVE-2026-3072MEDIUM4.3The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2026-30777MEDIUM6.5EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who ...
CVE-2026-29052MEDIUM6.1The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and ef...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now