2026 CVE Vulnerabilities
43,564 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45797 | MEDIUM | 6.4 | 0.4% | Jul 20, 2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated f... |
| CVE-2026-45712 | MEDIUM | 5.9 | 0.2% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?dat... |
| CVE-2026-45709 | MEDIUM | 5.8 | 0.2% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side R... |
| CVE-2026-32822 | MEDIUM | 6.1 | 0.2% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-26199 | MEDIUM | 6.5 | 0.3% | Jul 20, 2026 | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name`... |
| CVE-2026-26081 | MEDIUM | 4.8 | 0.4% | Jul 20, 2026 | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise... |
| CVE-2026-13724 | MEDIUM | 4.3 | 0.2% | Jul 20, 2026 | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an... |
| CVE-2026-59238 | MEDIUM | 6.9 | 0.3% | Jul 20, 2026 | Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderA... |
| CVE-2026-54685 | MEDIUM | 5.3 | 0.3% | Jul 20, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` a... |
| CVE-2026-46516 | MEDIUM | 4.8 | 0.3% | Jul 20, 2026 | Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js... |
| CVE-2026-45139 | MEDIUM | 6.5 | 0.3% | Jul 20, 2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enfo... |
| CVE-2026-16277 | MEDIUM | 6.5 | 0.3% | Jul 20, 2026 | A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcin... |
| CVE-2026-57311 | MEDIUM | 5.3 | 0.4% | Jul 20, 2026 | Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP... |
| CVE-2026-57310 | MEDIUM | 6.3 | 0.2% | Jul 20, 2026 | Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker... |
| CVE-2026-16244 | MEDIUM | 6.3 | — | Jul 20, 2026 | A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerabilit... |
| CVE-2026-63762 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript... |
| CVE-2026-63761 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES... |
| CVE-2026-63758 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenti... |
| CVE-2026-63753 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At... |
| CVE-2026-63752 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated ... |
| CVE-2026-63751 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo... |
| CVE-2026-63749 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis... |
| CVE-2026-63748 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac... |
| CVE-2026-63745 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof compos... |
| CVE-2026-63744 | MEDIUM | 5.1 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.5 contains a server-side request forgery vulnerability in the JWKS fetcher that follows HTTP redire... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now