2026 CVE Vulnerabilities

44,807 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-47129HIGH8.1NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Co...
CVE-2026-13381HIGH8.1VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/fil...
CVE-2026-13380HIGH7.5VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent...
CVE-2026-53593HIGH8.8FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylis...
CVE-2026-53591HIGH8.6FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthen...
CVE-2026-15788HIGH7.5BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory ju...
CVE-2026-64619HIGH8.7FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated a...
CVE-2026-64194HIGH7.5Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::Doma...
CVE-2026-63771HIGH7.1Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by ...
CVE-2026-63770HIGH8.2Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthentic...
CVE-2026-63769HIGH7.7Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport...
CVE-2026-63731HIGH7.7HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir...
CVE-2026-63108HIGH8.8Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attac...
CVE-2026-63107HIGH7.7LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey templat...
CVE-2026-60030HIGH8.7Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla...
CVE-2026-60028HIGH8.6Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Pa...
CVE-2026-60027HIGH8.7Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla...
CVE-2026-60026HIGH8.9Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension...
CVE-2026-48389HIGH7.8DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in...
CVE-2026-8170HIGH8.7The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize pat...
CVE-2026-8169HIGH8.7ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The cha...
CVE-2026-64612HIGH7.5A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without inst...
CVE-2026-55626HIGH7.3xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using...
CVE-2026-48812HIGH7.5FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's...
CVE-2026-34239HIGH7.5Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now