2026 CVE Vulnerabilities
43,564 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58624 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server... |
| CVE-2026-55219 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the... |
| CVE-2026-53596 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeSco... |
| CVE-2026-53594 | MEDIUM | 4.9 | 0.4% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Lo... |
| CVE-2026-44585 | MEDIUM | 5.4 | 0.3% | Jul 20, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the... |
| CVE-2026-44584 | MEDIUM | 4.3 | 0.2% | Jul 20, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the... |
| CVE-2026-44583 | MEDIUM | 5.3 | 0.4% | Jul 20, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the... |
| CVE-2026-53592 | MEDIUM | 4.6 | 0.1% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in th... |
| CVE-2026-44230 | MEDIUM | 6.1 | 0.2% | Jul 20, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10... |
| CVE-2026-44229 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to bo... |
| CVE-2026-63768 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows at... |
| CVE-2026-63730 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir... |
| CVE-2026-61901 | MEDIUM | 6.1 | 0.1% | Jul 20, 2026 | Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an ... |
| CVE-2026-60033 | MEDIUM | 5.1 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia i... |
| CVE-2026-60031 | MEDIUM | 6.9 | 0.3% | Jul 20, 2026 | Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page... |
| CVE-2026-60029 | MEDIUM | 5.1 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Pa... |
| CVE-2026-55639 | MEDIUM | 5.3 | 0.3% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Se... |
| CVE-2026-46715 | MEDIUM | 5.3 | 0.3% | Jul 20, 2026 | Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentica... |
| CVE-2026-45295 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tr... |
| CVE-2026-44228 | MEDIUM | 5.4 | 0.1% | Jul 20, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, conta... |
| CVE-2026-44227 | MEDIUM | 6.1 | 0.2% | Jul 20, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contai... |
| CVE-2026-26483 | MEDIUM | 6.1 | 0.2% | Jul 20, 2026 | Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template managemen... |
| CVE-2026-64207 | MEDIUM | 5.5 | 0.2% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: dualpi2: fix GSO backlog accounting Whe... |
| CVE-2026-64205 | MEDIUM | 5.5 | 0.2% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: i801: fix hardware state machine corruption in... |
| CVE-2026-64192 | MEDIUM | 5.5 | 0.2% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now