2026 CVE Vulnerabilities
44,807 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26197 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is cor... |
| CVE-2026-25039 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanit... |
| CVE-2026-21824 | HIGH | 8.8 | 0.2% | Jul 20, 2026 | HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user perso... |
| CVE-2026-63091 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-r... |
| CVE-2026-63090 | HIGH | 8.8 | 0.5% | Jul 20, 2026 | ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allo... |
| CVE-2026-62418 | HIGH | 8.1 | 0.2% | Jul 20, 2026 | Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Reso... |
| CVE-2026-54910 | HIGH | 7.7 | 0.3% | Jul 20, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` ... |
| CVE-2026-52349 | HIGH | 7.8 | 0.3% | Jul 20, 2026 | Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local a... |
| CVE-2026-46410 | HIGH | 8.7 | 0.3% | Jul 20, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may le... |
| CVE-2026-45270 | HIGH | 8.7 | 0.2% | Jul 20, 2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module... |
| CVE-2026-16252 | HIGH | 7.3 | — | Jul 20, 2026 | A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System ... |
| CVE-2026-16248 | HIGH | 8.8 | — | Jul 20, 2026 | A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the ... |
| CVE-2026-12080 | HIGH | 7.3 | — | Jul 20, 2026 | A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-a... |
| CVE-2026-64623 | HIGH | 8.8 | 0.2% | Jul 20, 2026 | Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the... |
| CVE-2026-63763 | HIGH | 8.8 | 0.2% | Jul 20, 2026 | SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileg... |
| CVE-2026-63760 | HIGH | 8.7 | 0.4% | Jul 20, 2026 | SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processin... |
| CVE-2026-63759 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annot... |
| CVE-2026-63757 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns at... |
| CVE-2026-63755 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses i... |
| CVE-2026-63754 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clause... |
| CVE-2026-63750 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket c... |
| CVE-2026-63747 | HIGH | 8.7 | 0.4% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is ... |
| CVE-2026-63746 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references.... |
| CVE-2026-63740 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users... |
| CVE-2026-63739 | HIGH | 8.3 | 0.3% | Jul 20, 2026 | SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows da... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now