2026 CVE Vulnerabilities
57,015 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15089 | CRITICAL | 9.1 | 0.4% | Jul 10, 2026 | Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*. |
| CVE-2026-15087 | MEDIUM | 5.9 | 0.2% | Jul 10, 2026 | vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*. |
| CVE-2026-15086 | MEDIUM | 5.9 | 0.2% | Jul 10, 2026 | vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter... |
| CVE-2026-14480 | CRITICAL | 9.9 | 0.6% | Jul 10, 2026 | OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload wor... |
| CVE-2026-14286 | — | — | — | Jul 10, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-11915 | MEDIUM | 5.9 | 0.2% | Jul 10, 2026 | vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions... |
| CVE-2026-11914 | MEDIUM | 5.9 | 0.2% | Jul 10, 2026 | vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*. |
| CVE-2026-11913 | CRITICAL | 9.8 | 0.2% | Jul 10, 2026 | vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. |
| CVE-2026-59155 | MEDIUM | 6.9 | 0.3% | Jul 10, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET ... |
| CVE-2026-58591 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox al... |
| CVE-2026-58590 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: f... |
| CVE-2026-58589 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: f... |
| CVE-2026-58588 | MEDIUM | 6.1 | 0.3% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canv... |
| CVE-2026-58587 | MEDIUM | 6.1 | 0.3% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canv... |
| CVE-2026-58503 | MEDIUM | 6.9 | 0.4% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via... |
| CVE-2026-57584 | HIGH | 8.7 | 0.4% | Jul 10, 2026 | Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a def... |
| CVE-2026-55884 | CRITICAL | 9.2 | 0.4% | Jul 10, 2026 | Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP... |
| CVE-2026-55883 | HIGH | 8.3 | 0.2% | Jul 10, 2026 | Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebS... |
| CVE-2026-55882 | HIGH | 8.3 | 0.4% | Jul 10, 2026 | Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD serv... |
| CVE-2026-55852 | HIGH | 8.6 | 0.5% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Imp... |
| CVE-2026-55810 | HIGH | 8.1 | 0.2% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphin... |
| CVE-2026-55809 | HIGH | 8.1 | 0.3% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance f... |
| CVE-2026-55808 | MEDIUM | 5.4 | 0.1% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core... |
| CVE-2026-55807 | LOW | 3.1 | 0.1% | Jul 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af... |
| CVE-2026-55806 | MEDIUM | 5.9 | 0.2% | Jul 10, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now