2026 CVE Vulnerabilities

64,732 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-96875MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ...
CVE-2026-93682MEDIUM5.8When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redi...
CVE-2026-100373MEDIUM4.1OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function...
CVE-2026-97895MEDIUM6.3A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webk...
CVE-2026-84463MEDIUM6.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing r...
CVE-2026-84461MEDIUM6.9Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an att...
CVE-2026-84460MEDIUM5.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the ...
CVE-2026-63216MEDIUM5.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are render...
CVE-2026-63208MEDIUM5.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails...
CVE-2026-63207MEDIUM6.9Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator c...
CVE-2026-63206MEDIUM5.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which block...
CVE-2026-63205MEDIUM5.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email s...
CVE-2026-63006MEDIUM5.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound ...
CVE-2026-61855MEDIUM5.3Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad...
CVE-2026-55217MEDIUM5.3GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authentica...
CVE-2026-53628MEDIUM5.9GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding th...
CVE-2026-53627MEDIUM6GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user c...
CVE-2026-49469MEDIUM4.6GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner o...
CVE-2026-45801MEDIUM5.3GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user witho...
CVE-2026-100306MEDIUM5.3TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the...
CVE-2026-100305MEDIUM4.3TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /...
CVE-2026-100304MEDIUM5.3TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open wh...
CVE-2026-100303MEDIUM5.4TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes a...
CVE-2026-100192MEDIUM6.5X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint withou...
CVE-2026-97886MEDIUM6.3A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now