2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27465MEDIUM6.5Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration A...
CVE-2026-25963MEDIUM6.5Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s ce...
CVE-2026-24004MEDIUM5.3Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub...
CVE-2026-23999MEDIUM5.5Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs ...
CVE-2026-2506MEDIUM6.1The EM Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin...
CVE-2026-2499MEDIUM4.4The Custom Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2026-2498MEDIUM4.4The WP Social Meta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ...
CVE-2026-2489MEDIUM4.4The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea ...
CVE-2026-2029MEDIUM6.4The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_...
CVE-2026-27973MEDIUM4.8Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists i...
CVE-2026-27970MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-27968MEDIUM4.3Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, Rep...
CVE-2026-27954MEDIUM6.5Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52,...
CVE-2026-27948MEDIUM6.1Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via U...
CVE-2026-27943MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. In versions up ...
CVE-2026-27902MEDIUM5.4Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly esca...
CVE-2026-27901MEDIUM6.1Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textConte...
CVE-2026-27887MEDIUM6.9Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin...
CVE-2026-22728MEDIUM4.9Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow. The rotati...
CVE-2026-27946MEDIUM6.5ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's...
CVE-2026-27945MEDIUM6.5ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta i...
CVE-2026-27884MEDIUM5.3NetExec is a network execution tool. Prior to version 1.5.1, the module spider_plus improperly creates the output file a...
CVE-2026-27840MEDIUM4.3ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11....
CVE-2026-27933MEDIUM6.8Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ...
CVE-2026-27799MEDIUM4.4ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now