2026 CVE Vulnerabilities

56,994 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52838LOW2.6Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custo...
CVE-2026-23573MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2026-15699MEDIUM6.3A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the f...
CVE-2026-15698MEDIUM6.3A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of th...
CVE-2026-15697MEDIUM6.3A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/...
CVE-2026-15392HIGH7.7DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The co...
CVE-2026-14504HIGH8.2An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on ...
CVE-2026-12707HIGH7.5Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of p...
CVE-2026-12659HIGH8.7A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of e...
CVE-2026-12523HIGH7.5Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by mea...
CVE-2026-11944MEDIUM6.5openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment ...
CVE-2026-11917HIGH7.2A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of fi...
CVE-2026-11403HIGH8.7A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to...
CVE-2026-9653HIGH8.7A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper va...
CVE-2026-9140HIGH8.7A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP un...
CVE-2026-8590HIGH8.7Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Cons...
CVE-2026-60114HIGH8.7Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attacke...
CVE-2026-58479CRITICAL9.8Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional ...
CVE-2026-58478MEDIUM6.5Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability...
CVE-2026-58477HIGH7.5Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauth...
CVE-2026-58476HIGH8.1Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that al...
CVE-2026-58475MEDIUM6.1Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that a...
CVE-2026-52837MEDIUM6.9Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule ...
CVE-2026-51105HIGH7.5Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via t...
CVE-2026-15736HIGH8.3Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now