2026 CVE Vulnerabilities
43,990 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13241 | MEDIUM | 6.5 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs version... |
| CVE-2026-13240 | MEDIUM | 6.5 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs version... |
| CVE-2026-13239 | MEDIUM | 6.5 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from ... |
| CVE-2026-13238 | MEDIUM | 4.8 | 0.1% | Jul 10, 2026 | Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue a... |
| CVE-2026-13237 | MEDIUM | 4.8 | 0.2% | Jul 10, 2026 | Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents version... |
| CVE-2026-13236 | MEDIUM | 4.2 | 0.1% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions:... |
| CVE-2026-13234 | MEDIUM | 6.1 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artific... |
| CVE-2026-13231 | MEDIUM | 6.1 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Co... |
| CVE-2026-11908 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allo... |
| CVE-2026-10770 | MEDIUM | 6.1 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam b... |
| CVE-2026-10769 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Co... |
| CVE-2026-57575 | MEDIUM | 6.9 | 0.3% | Jul 10, 2026 | Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a Server-Side Request Fo... |
| CVE-2026-57230 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise ed... |
| CVE-2026-57221 | MEDIUM | 5 | 0.3% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform aut... |
| CVE-2026-57218 | MEDIUM | 6.5 | 0.3% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep re... |
| CVE-2026-57217 | MEDIUM | 6.5 | 0.3% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization ... |
| CVE-2026-57214 | MEDIUM | 5.4 | 0.3% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose ... |
| CVE-2026-57213 | MEDIUM | 4.8 | 0.2% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_manag... |
| CVE-2026-55664 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table ... |
| CVE-2026-13039 | MEDIUM | 5.3 | 0.3% | Jul 10, 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to a... |
| CVE-2026-57157 | MEDIUM | 6.5 | 0.5% | Jul 10, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, FreeRDP server implementations with th... |
| CVE-2026-55515 | MEDIUM | 5 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authoriz... |
| CVE-2026-55481 | MEDIUM | 4.8 | 0.4% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related br... |
| CVE-2026-55479 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorize... |
| CVE-2026-55475 | MEDIUM | 5.7 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV impo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now