2026 CVE Vulnerabilities

43,564 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-58624MEDIUM5.4Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server...
CVE-2026-55219MEDIUM5.3Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the...
CVE-2026-53596MEDIUM5.3FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeSco...
CVE-2026-53594MEDIUM4.9FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Lo...
CVE-2026-44585MEDIUM5.4Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the...
CVE-2026-44584MEDIUM4.3Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the...
CVE-2026-44583MEDIUM5.3Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the...
CVE-2026-53592MEDIUM4.6FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in th...
CVE-2026-44230MEDIUM6.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10...
CVE-2026-44229MEDIUM5.4RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to bo...
CVE-2026-63768MEDIUM5.3cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows at...
CVE-2026-63730MEDIUM5.3HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir...
CVE-2026-61901MEDIUM6.1Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an ...
CVE-2026-60033MEDIUM5.1Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia i...
CVE-2026-60031MEDIUM6.9Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page...
CVE-2026-60029MEDIUM5.1Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Pa...
CVE-2026-55639MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Se...
CVE-2026-46715MEDIUM5.3Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentica...
CVE-2026-45295MEDIUM6.5FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tr...
CVE-2026-44228MEDIUM5.4RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, conta...
CVE-2026-44227MEDIUM6.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contai...
CVE-2026-26483MEDIUM6.1Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template managemen...
CVE-2026-64207MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: dualpi2: fix GSO backlog accounting Whe...
CVE-2026-64205MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i2c: i801: fix hardware state machine corruption in...
CVE-2026-64192MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now