2026 CVE Vulnerabilities
57,015 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12761 | CRITICAL | 9.8 | 0.5% | Jul 10, 2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to auth... |
| CVE-2026-57850 | HIGH | 8.7 | 0.4% | Jul 10, 2026 | RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a l... |
| CVE-2026-57158 | CRITICAL | 9.1 | 0.7% | Jul 10, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GF... |
| CVE-2026-57157 | MEDIUM | 6.5 | 0.5% | Jul 10, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with th... |
| CVE-2026-57156 | CRITICAL | 9.8 | 0.7% | Jul 10, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients conta... |
| CVE-2026-55827 | HIGH | 8.8 | 0.5% | Jul 10, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-... |
| CVE-2026-55789 | HIGH | 8.5 | 0.3% | Jul 10, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML app... |
| CVE-2026-55515 | MEDIUM | 5 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authoriz... |
| CVE-2026-55481 | MEDIUM | 4.8 | 0.4% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related br... |
| CVE-2026-55479 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorize... |
| CVE-2026-55475 | MEDIUM | 5.7 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV impo... |
| CVE-2026-55469 | MEDIUM | 6.5 | 0.4% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update p... |
| CVE-2026-55466 | HIGH | 8.7 | 0.4% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP... |
| CVE-2026-55462 | MEDIUM | 4.3 | 0.3% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authoriz... |
| CVE-2026-55461 | MEDIUM | 6.1 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the ... |
| CVE-2026-55452 | HIGH | 7.3 | 0.3% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent ... |
| CVE-2026-55377 | HIGH | 8.1 | 0.3% | Jul 10, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-... |
| CVE-2026-55370 | MEDIUM | 6.4 | 0.2% | Jul 10, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verifi... |
| CVE-2026-54714 | MEDIUM | 6.1 | 0.3% | Jul 10, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SA... |
| CVE-2026-15295 | MEDIUM | 4.4 | 0.2% | Jul 10, 2026 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm... |
| CVE-2026-11321 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL ... |
| CVE-2026-6872 | — | — | — | Jul 10, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-6212 | HIGH | 8.8 | — | Jul 10, 2026 | Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Pri... |
| CVE-2026-61461 | HIGH | 8.8 | 0.4% | Jul 10, 2026 | Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers ... |
| CVE-2026-61460 | HIGH | 8.8 | — | Jul 10, 2026 | Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now