2026 CVE Vulnerabilities

65,368 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100718HIGH7.1Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When ...
CVE-2026-100717CRITICAL9.9froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return ...
CVE-2026-100716CRITICAL9.9Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails...
CVE-2026-100715CRITICAL9.6Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task...
CVE-2026-100714CRITICAL9.1Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings h...
CVE-2026-100713HIGH7.8Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cr...
CVE-2026-100712MEDIUM6.5froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET r...
CVE-2026-100711HIGH7.5froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user p...
CVE-2026-100710MEDIUM4.9Froxlor through 2.3.10 does not filter sensitive columns from API responses: Domains::get(), Domains::listing(), SubDoma...
CVE-2026-100709HIGH7.5Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the a...
CVE-2026-100708HIGH7.1Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in t...
CVE-2026-100707HIGH7.7Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources ...
CVE-2026-100706CRITICAL9.9kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace...
CVE-2026-100705HIGH7.6Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.2...
CVE-2026-100704HIGH7.7Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyvern...
CVE-2026-100703HIGH7.7Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it...
CVE-2026-100702MEDIUM5.9Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, all...
CVE-2026-100701MEDIUM5.9Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each c...
CVE-2026-100700HIGH7.5nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex patter...
CVE-2026-100699MEDIUM5.3Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser)...
CVE-2026-100698MEDIUM5.8Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/f...
CVE-2026-100697HIGH8.6Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6....
CVE-2026-100696MEDIUM5.8Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the option...
CVE-2026-100695MEDIUM6.1Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpol...
CVE-2026-100694MEDIUM6.1Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now