2026 CVE Vulnerabilities

53,638 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-22242MEDIUM4.9CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in...
CVE-2026-21894MEDIUM6.5n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass v...
CVE-2026-21874MEDIUM5.3NiceGUI is a Python-based UI framework. From versions v2.10.0 to 3.4.1, an unauthenticated attacker can exhaust Redis co...
CVE-2026-21873MEDIUM6.1NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the pushstate event l...
CVE-2026-21872MEDIUM6.1NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the click event liste...
CVE-2026-21871MEDIUM6.1NiceGUI is a Python-based UI framework. From versions 2.13.0 to 3.4.1, there is a XSS risk in NiceGUI when developers pa...
CVE-2026-0676MEDIUM5.3Missing Authorization vulnerability in G5Theme Zorka zorka allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2026-0674MEDIUM4.3Missing Authorization vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Exploiting Incorrectly Con...
CVE-2026-0707MEDIUM5.3A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of ...
CVE-2026-21883MEDIUM5.4Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured ...
CVE-2026-21880MEDIUM5.3Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection ...
CVE-2026-21879MEDIUM6.1Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Op...
CVE-2026-21859MEDIUM5.3Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (S...
CVE-2026-21695MEDIUM4.3Titra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnera...
CVE-2026-21857MEDIUM6.5REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions ca...
CVE-2026-21851MEDIUM5.3MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a P...
CVE-2026-21691MEDIUM6.5iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio...
CVE-2026-21690MEDIUM6.3iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio...
CVE-2026-21689MEDIUM6.5iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio...
CVE-2026-22188MEDIUM5.5The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due...
CVE-2026-22185MEDIUM4.6OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a...
CVE-2026-21855MEDIUM6.1The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, a reflected Cross Site Scrip...
CVE-2026-0670MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-22539MEDIUM5.3As the service interaction is performed without authentication, an attacker with some knowledge of the protocol could ob...
CVE-2026-21506MEDIUM5.5iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now