2026 CVE Vulnerabilities
43,970 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58503 | MEDIUM | 6.9 | 0.4% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via... |
| CVE-2026-55808 | MEDIUM | 5.4 | 0.1% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core... |
| CVE-2026-55806 | MEDIUM | 5.9 | 0.2% | Jul 10, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is... |
| CVE-2026-55804 | MEDIUM | 5.9 | 0.2% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow... |
| CVE-2026-55803 | MEDIUM | 5.9 | 0.2% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow... |
| CVE-2026-55187 | MEDIUM | 5.8 | 0.3% | Jul 10, 2026 | Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is ... |
| CVE-2026-52761 | MEDIUM | 5.3 | 0.4% | Jul 10, 2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.... |
| CVE-2026-49844 | MEDIUM | 5.9 | 0.8% | Jul 10, 2026 | Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces ... |
| CVE-2026-48127 | MEDIUM | 5.3 | 0.4% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach... |
| CVE-2026-47422 | MEDIUM | 5.3 | 0.3% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked approp... |
| CVE-2026-42219 | MEDIUM | 6.9 | 0.5% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, path traversal via download_backups was... |
| CVE-2026-15085 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO ... |
| CVE-2026-15084 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Patterns... |
| CVE-2026-15083 | MEDIUM | 4.2 | 0.2% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Cond... |
| CVE-2026-15082 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Siteimprove... |
| CVE-2026-15080 | MEDIUM | 4.3 | 0.1% | Jul 10, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. ... |
| CVE-2026-15079 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Login Disable allows Brute Force. This... |
| CVE-2026-13243 | MEDIUM | 4.8 | 0.1% | Jul 10, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue... |
| CVE-2026-13242 | MEDIUM | 6.5 | 0.2% | Jul 10, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation... |
| CVE-2026-13241 | MEDIUM | 6.5 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs version... |
| CVE-2026-13240 | MEDIUM | 6.5 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs version... |
| CVE-2026-13239 | MEDIUM | 6.5 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from ... |
| CVE-2026-13238 | MEDIUM | 4.8 | 0.1% | Jul 10, 2026 | Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue a... |
| CVE-2026-13237 | MEDIUM | 4.8 | 0.2% | Jul 10, 2026 | Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents version... |
| CVE-2026-13236 | MEDIUM | 4.2 | 0.1% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions:... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now