2026 CVE Vulnerabilities
44,807 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47129 | HIGH | 8.1 | 0.2% | Jul 20, 2026 | NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Co... |
| CVE-2026-13381 | HIGH | 8.1 | 0.2% | Jul 20, 2026 | VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/fil... |
| CVE-2026-13380 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent... |
| CVE-2026-53593 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylis... |
| CVE-2026-53591 | HIGH | 8.6 | 0.2% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthen... |
| CVE-2026-15788 | HIGH | 7.5 | 0.1% | Jul 20, 2026 | BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory ju... |
| CVE-2026-64619 | HIGH | 8.7 | 0.2% | Jul 20, 2026 | FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated a... |
| CVE-2026-64194 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::Doma... |
| CVE-2026-63771 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by ... |
| CVE-2026-63770 | HIGH | 8.2 | 0.2% | Jul 20, 2026 | Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthentic... |
| CVE-2026-63769 | HIGH | 7.7 | 0.2% | Jul 20, 2026 | Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport... |
| CVE-2026-63731 | HIGH | 7.7 | 0.2% | Jul 20, 2026 | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir... |
| CVE-2026-63108 | HIGH | 8.8 | 1.9% | Jul 20, 2026 | Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attac... |
| CVE-2026-63107 | HIGH | 7.7 | 0.2% | Jul 20, 2026 | LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey templat... |
| CVE-2026-60030 | HIGH | 8.7 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla... |
| CVE-2026-60028 | HIGH | 8.6 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Pa... |
| CVE-2026-60027 | HIGH | 8.7 | 0.3% | Jul 20, 2026 | Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla... |
| CVE-2026-60026 | HIGH | 8.9 | 0.3% | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension... |
| CVE-2026-48389 | HIGH | 7.8 | 0.2% | Jul 20, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in... |
| CVE-2026-8170 | HIGH | 8.7 | 0.4% | Jul 20, 2026 | The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize pat... |
| CVE-2026-8169 | HIGH | 8.7 | 0.3% | Jul 20, 2026 | ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The cha... |
| CVE-2026-64612 | HIGH | 7.5 | 0.4% | Jul 20, 2026 | A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without inst... |
| CVE-2026-55626 | HIGH | 7.3 | 0.1% | Jul 20, 2026 | xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using... |
| CVE-2026-48812 | HIGH | 7.5 | 0.4% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's... |
| CVE-2026-34239 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now