2026 CVE Vulnerabilities

43,308 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-16767MEDIUM6.5A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file sr...
CVE-2026-16764MEDIUM6.3A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file do...
CVE-2026-16763MEDIUM5.3A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown funct...
CVE-2026-39155MEDIUM6.5Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name ...
CVE-2026-15968MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr...
CVE-2026-64785MEDIUM5.3SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters r...
CVE-2026-48013MEDIUM4.1Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint ...
CVE-2026-48012MEDIUM4.3Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO ...
CVE-2026-12353MEDIUM5.3An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly se...
CVE-2026-65010MEDIUM6.6Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that a...
CVE-2026-65920MEDIUM5.3Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_...
CVE-2026-65763MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs...
CVE-2026-65762MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user i...
CVE-2026-65699MEDIUM4.2AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica...
CVE-2026-47769MEDIUM5.3APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr...
CVE-2026-47755MEDIUM6.5ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi...
CVE-2026-65698MEDIUM6Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace...
CVE-2026-65697MEDIUM6.1Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that...
CVE-2026-65696MEDIUM5.4Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip...
CVE-2026-16768MEDIUM5.3A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale...
CVE-2026-48539MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf...
CVE-2026-48538MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat...
CVE-2026-48537MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati...
CVE-2026-48536MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio...
CVE-2026-48535MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configurati...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now