2026 CVE Vulnerabilities
43,890 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62641 | MEDIUM | 6.5 | 0.2% | Jul 14, 2026 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft... |
| CVE-2026-60119 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event cre... |
| CVE-2026-60118 | MEDIUM | 6.9 | 0.2% | Jul 14, 2026 | Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated ... |
| CVE-2026-59840 | MEDIUM | 4.3 | 0.2% | Jul 14, 2026 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v... |
| CVE-2026-59839 | MEDIUM | 5.5 | 0.2% | Jul 14, 2026 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0... |
| CVE-2026-59837 | MEDIUM | 6.6 | 0.6% | Jul 14, 2026 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM ... |
| CVE-2026-23573 | MEDIUM | 6.1 | 0.3% | Jul 14, 2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi... |
| CVE-2026-15699 | MEDIUM | 6.3 | — | Jul 14, 2026 | A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the f... |
| CVE-2026-15698 | MEDIUM | 6.3 | — | Jul 14, 2026 | A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of th... |
| CVE-2026-15697 | MEDIUM | 6.3 | 0.3% | Jul 14, 2026 | A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/... |
| CVE-2026-11944 | MEDIUM | 6.5 | — | Jul 14, 2026 | openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment ... |
| CVE-2026-58478 | MEDIUM | 6.5 | 0.3% | Jul 14, 2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability... |
| CVE-2026-58475 | MEDIUM | 6.1 | 0.2% | Jul 14, 2026 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that a... |
| CVE-2026-52837 | MEDIUM | 6.9 | 0.4% | Jul 14, 2026 | Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule ... |
| CVE-2026-14903 | MEDIUM | 6.5 | 1.0% | Jul 14, 2026 | Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary fil... |
| CVE-2026-14902 | MEDIUM | 6.1 | 0.5% | Jul 14, 2026 | An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users ... |
| CVE-2026-10670 | MEDIUM | 5.5 | 0.1% | Jul 14, 2026 | The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kerne... |
| CVE-2026-53566 | MEDIUM | 6.8 | 0.1% | Jul 14, 2026 | Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Ac... |
| CVE-2026-62393 | MEDIUM | 4.3 | 0.5% | Jul 14, 2026 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job... |
| CVE-2026-49488 | MEDIUM | 6.5 | 0.7% | Jul 14, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. Th... |
| CVE-2026-15719 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.... |
| CVE-2026-15718 | MEDIUM | 4.3 | 0.2% | Jul 14, 2026 | We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.... |
| CVE-2026-15305 | MEDIUM | 6.3 | 0.2% | Jul 14, 2026 | Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowed... |
| CVE-2026-12588 | MEDIUM | 6 | 0.2% | Jul 14, 2026 | An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The m... |
| CVE-2026-9341 | MEDIUM | 4.3 | — | Jul 14, 2026 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Di... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now