2026 CVE Vulnerabilities
43,494 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16449 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted elem... |
| CVE-2026-65051 | MEDIUM | 6.9 | 0.3% | Jul 21, 2026 | Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability tha... |
| CVE-2026-56584 | MEDIUM | 5.3 | 0.2% | Jul 21, 2026 | HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software... |
| CVE-2026-47122 | MEDIUM | 4.2 | 0.1% | Jul 21, 2026 | Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `... |
| CVE-2026-16448 | MEDIUM | 6.3 | — | Jul 21, 2026 | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-32... |
| CVE-2026-11876 | MEDIUM | 5 | 0.2% | Jul 21, 2026 | In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper ... |
| CVE-2026-9499 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is ... |
| CVE-2026-59848 | MEDIUM | 5.3 | 0.3% | Jul 21, 2026 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep ... |
| CVE-2026-47121 | MEDIUM | 6.1 | 0.2% | Jul 21, 2026 | Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `re... |
| CVE-2026-8285 | MEDIUM | 4.3 | 0.2% | Jul 21, 2026 | Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Exces... |
| CVE-2026-8284 | MEDIUM | 6.1 | 0.1% | Jul 21, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data ... |
| CVE-2026-6792 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access ... |
| CVE-2026-16403 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16397 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153. |
| CVE-2026-65009 | MEDIUM | 5.3 | 0.2% | Jul 21, 2026 | OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint th... |
| CVE-2026-64628 | MEDIUM | 5.4 | 0.1% | Jul 21, 2026 | Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection s... |
| CVE-2026-64627 | MEDIUM | 6.9 | 0.3% | Jul 21, 2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerabilit... |
| CVE-2026-59845 | MEDIUM | 5.9 | 0.1% | Jul 21, 2026 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; durin... |
| CVE-2026-59844 | MEDIUM | 6.5 | 0.5% | Jul 21, 2026 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large leng... |
| CVE-2026-59843 | MEDIUM | 6.5 | 0.5% | Jul 21, 2026 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN... |
| CVE-2026-59842 | MEDIUM | 5.3 | 0.4% | Jul 21, 2026 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than... |
| CVE-2026-16461 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), v... |
| CVE-2026-1372 | MEDIUM | 4.3 | 0.2% | Jul 21, 2026 | The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in... |
| CVE-2026-15145 | MEDIUM | 6.4 | 0.2% | Jul 21, 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-8593 | MEDIUM | 5.3 | 0.2% | Jul 21, 2026 | Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now