2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-55636MEDIUM5.7Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates...
CVE-2026-55591MEDIUM5.8Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in sr...
CVE-2026-54724MEDIUM6.1Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalid...
CVE-2026-50024MEDIUM5.3GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_ta...
CVE-2026-47215MEDIUM4.8SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4....
CVE-2026-44282MEDIUM4.8Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or electio...
CVE-2026-44163MEDIUM5.3fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0....
CVE-2026-92082MEDIUM6.3By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute for...
CVE-2026-91842MEDIUM4.1A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert o...
CVE-2026-90439MEDIUM6.5NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL v...
CVE-2026-88618MEDIUM6.51024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This ...
CVE-2026-55650MEDIUM4.4Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2...
CVE-2026-55617MEDIUM6.9Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic...
CVE-2026-54637MEDIUM5.5Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the schedule...
CVE-2026-54254MEDIUM5.9Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler ...
CVE-2026-54168MEDIUM6.5Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8...
CVE-2026-52724MEDIUM5.8Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2...
CVE-2026-50166MEDIUM5.5Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2...
CVE-2026-49446MEDIUM6.1Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as ...
CVE-2026-48987MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload...
CVE-2026-48737MEDIUM4.9pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/p...
CVE-2026-48722MEDIUM5.5Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth lo...
CVE-2026-47780MEDIUM6.9free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and H...
CVE-2026-25826MEDIUM4.9An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be s...
CVE-2026-92078MEDIUM6.5Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now