2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-102261MEDIUM5.4A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/ca...
CVE-2026-97029MEDIUM5.7Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls ...
CVE-2026-97024HIGH7.1A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious...
CVE-2026-102422HIGH8.1shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of...
CVE-2026-102414LOW3.7pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallba...
CVE-2026-102249HIGH7.3A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /common...
CVE-2026-102248HIGH7.3A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login ...
CVE-2026-102247MEDIUM6.8A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file ap...
CVE-2026-102245HIGH7.3A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the fi...
CVE-2026-97685HIGH7.1An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an author...
CVE-2026-102244MEDIUM4.3A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file sur...
CVE-2026-102243HIGH7.4A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the fil...
CVE-2026-102241LOW2.7A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file ...
CVE-2026-96326HIGH7.2The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2026-102240CRITICAL10A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/n...
CVE-2026-101878HIGH7.5Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExte...
CVE-2026-101860HIGH8.8A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::a...
CVE-2026-101859MEDIUM5.4A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escap...
CVE-2026-101858MEDIUM4.7A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of t...
CVE-2026-101354CRITICAL9.6A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of ...
CVE-2026-102374MEDIUM6.1GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that doub...
CVE-2026-102373MEDIUM6.5GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in t...
CVE-2026-102372MEDIUM6.1GestSup versions before 3.2.62 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthe...
CVE-2026-101281HIGH7.3A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function op...
CVE-2026-101280HIGH7.3A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now