2026 CVE Vulnerabilities
43,894 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58228 | MEDIUM | 5.1 | — | Jul 13, 2026 | Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validat... |
| CVE-2026-49971 | MEDIUM | 6.1 | 0.2% | Jul 13, 2026 | Laravel-Mediable before 7.0.0 contains a stored cross-site scripting vulnerability that allows authenticated or anonymou... |
| CVE-2026-14906 | MEDIUM | 5.3 | 0.2% | Jul 13, 2026 | Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within t... |
| CVE-2026-61505 | MEDIUM | 6.9 | 0.5% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthentica... |
| CVE-2026-61504 | MEDIUM | 5.4 | 0.2% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be ... |
| CVE-2026-61503 | MEDIUM | 6.9 | 0.3% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the ... |
| CVE-2026-61502 | MEDIUM | 5.1 | 0.2% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its... |
| CVE-2026-61501 | MEDIUM | 6.1 | 0.3% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote u... |
| CVE-2026-60103 | MEDIUM | 6.8 | 0.1% | Jul 13, 2026 | Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or rea... |
| CVE-2026-53365 | MEDIUM | 5.5 | 0.1% | Jul 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb... |
| CVE-2026-53364 | MEDIUM | 5.5 | 0.1% | Jul 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_... |
| CVE-2026-15559 | MEDIUM | 6.3 | — | Jul 13, 2026 | A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the... |
| CVE-2026-62147 | MEDIUM | 6.5 | — | Jul 13, 2026 | The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API respons... |
| CVE-2026-15558 | MEDIUM | 6.3 | — | Jul 13, 2026 | A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issu... |
| CVE-2026-9824 | MEDIUM | 4.3 | — | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels per... |
| CVE-2026-6541 | MEDIUM | 4.3 | — | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration change... |
| CVE-2026-4765 | MEDIUM | 5.1 | — | Jul 13, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in the RD Station Conversas chat. The vulnerability resides in the ‘name... |
| CVE-2026-61985 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl... |
| CVE-2026-61983 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc... |
| CVE-2026-61977 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-sea... |
| CVE-2026-61976 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Ele... |
| CVE-2026-61975 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-re... |
| CVE-2026-61970 | MEDIUM | 4.9 | 0.2% | Jul 13, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbn... |
| CVE-2026-61968 | MEDIUM | 5.4 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-61958 | MEDIUM | 5.4 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now