2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-27735MEDIUM6.5Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp...
CVE-2026-27711MEDIUM6.6NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, ...
CVE-2026-27710MEDIUM5NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, ...
CVE-2026-27709MEDIUM6.6NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, ...
CVE-2026-3209MEDIUM6.3A vulnerability has been found in fosrl Pangolin up to 1.15.4-s.3. This affects the function verifyRoleAccess/verifyApiK...
CVE-2026-27578MEDIUM5.4n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user...
CVE-2026-2694MEDIUM5.4The The Events Calendar plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to ...
CVE-2026-27116MEDIUM6.1Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, a reflected HTML injection vulne...
CVE-2026-26985MEDIUM6.5LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-2845MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18....
CVE-2026-27015MEDIUM6.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `sma...
CVE-2026-26271MEDIUM5.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_...
CVE-2026-1747MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18....
CVE-2026-0752MEDIUM6.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 1...
CVE-2026-2636MEDIUM5.5This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads ...
CVE-2026-25736MEDIUM4.8Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da...
CVE-2026-25735MEDIUM4.8Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da...
CVE-2026-25734MEDIUM4.8Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da...
CVE-2026-25733MEDIUM5.4Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da...
CVE-2026-25138MEDIUM5.3Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da...
CVE-2026-25136MEDIUM6.1Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da...
CVE-2026-3221MEDIUM4.9Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which ...
CVE-2026-25930MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-25929MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-25743MEDIUM4.8OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now