2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-25774MEDIUM5.3Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-25195MEDIUM6.6An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack...
CVE-2026-22878MEDIUM5.3Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-3269MEDIUM6.5A flaw has been found in psi-probe PSI Probe up to 5.3.0. The impacted element is the function handleRequestInternal of ...
CVE-2026-27773MEDIUM5.3Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-22890MEDIUM5.3Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-20733MEDIUM5.3Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-3268MEDIUM4.3A vulnerability was detected in psi-probe PSI Probe up to 5.3.0. The affected element is an unknown function of the file...
CVE-2026-28230MEDIUM6.3SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger se...
CVE-2026-28226MEDIUM6.5Phishing Club is a phishing simulation and man-in-the-middle framework. Prior to version 1.30.2, an authenticated SQL in...
CVE-2026-28225MEDIUM6.5Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ...
CVE-2026-28217MEDIUM6.5hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query ac...
CVE-2026-28208MEDIUM5.9Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `...
CVE-2026-27839MEDIUM4.3wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values`...
CVE-2026-28219MEDIUM4.3Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper author...
CVE-2026-28218MEDIUM5.4Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access c...
CVE-2026-27835MEDIUM4.3wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet`...
CVE-2026-27457MEDIUM4.3Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`...
CVE-2026-27154MEDIUM6.1Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, a user full name c...
CVE-2026-27162MEDIUM4.9Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `posts_nearby` was...
CVE-2026-27149MEDIUM6.5Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, SQL injection in P...
CVE-2026-27021MEDIUM5.3Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoin...
CVE-2026-26973MEDIUM4.3Discourse is an open source discussion platform. Versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 have an IDOR (Insec...
CVE-2026-22722MEDIUM6.1A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null poi...
CVE-2026-22715MEDIUM5.9VMWare Workstation and Fusion contain a logic flaw in the management of network packets.  Known attack vectors: A malic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now