2026 CVE Vulnerabilities
65,524 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97160 | CRITICAL | 9.4 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0... |
| CVE-2026-94132 | CRITICAL | 9.5 | — | Sep 26, 2026 | Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterpri... |
| CVE-2026-94131 | HIGH | 8.3 | — | Sep 26, 2026 | Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 ... |
| CVE-2026-94130 | CRITICAL | 9.3 | — | Sep 26, 2026 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injectio... |
| CVE-2026-100720 | HIGH | 8.7 | — | Sep 26, 2026 | Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authen... |
| CVE-2026-100719 | MEDIUM | 6.5 | — | Sep 26, 2026 | Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command t... |
| CVE-2026-100718 | HIGH | 7.1 | — | Sep 26, 2026 | Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When ... |
| CVE-2026-100717 | CRITICAL | 9.9 | — | Sep 26, 2026 | froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return ... |
| CVE-2026-100716 | CRITICAL | 9.9 | — | Sep 26, 2026 | Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails... |
| CVE-2026-100715 | CRITICAL | 9.6 | — | Sep 26, 2026 | Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task... |
| CVE-2026-100714 | CRITICAL | 9.1 | — | Sep 26, 2026 | Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings h... |
| CVE-2026-100713 | HIGH | 7.8 | — | Sep 26, 2026 | Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cr... |
| CVE-2026-100712 | MEDIUM | 6.5 | — | Sep 26, 2026 | froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET r... |
| CVE-2026-100711 | HIGH | 7.5 | — | Sep 26, 2026 | froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user p... |
| CVE-2026-100710 | MEDIUM | 4.9 | — | Sep 26, 2026 | Froxlor through 2.3.10 does not filter sensitive columns from API responses: Domains::get(), Domains::listing(), SubDoma... |
| CVE-2026-100709 | HIGH | 7.5 | — | Sep 26, 2026 | Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the a... |
| CVE-2026-100708 | HIGH | 7.1 | — | Sep 26, 2026 | Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in t... |
| CVE-2026-100707 | HIGH | 7.7 | — | Sep 26, 2026 | Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources ... |
| CVE-2026-100706 | CRITICAL | 9.9 | — | Sep 26, 2026 | kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace... |
| CVE-2026-100705 | HIGH | 7.6 | — | Sep 26, 2026 | Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.2... |
| CVE-2026-100704 | HIGH | 7.7 | — | Sep 26, 2026 | Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyvern... |
| CVE-2026-100703 | HIGH | 7.7 | — | Sep 26, 2026 | Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it... |
| CVE-2026-100702 | MEDIUM | 5.9 | — | Sep 26, 2026 | Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, all... |
| CVE-2026-100701 | MEDIUM | 5.9 | — | Sep 26, 2026 | Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each c... |
| CVE-2026-100700 | HIGH | 7.5 | — | Sep 26, 2026 | nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex patter... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now