2026 CVE Vulnerabilities
51,046 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58047 | MEDIUM | 5.6 | 0.5% | Jul 31, 2026 | HTTP Smuggling in cPanel allows potential leak of credentials. |
| CVE-2026-54707 | MEDIUM | 5.4 | — | Jul 31, 2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien... |
| CVE-2026-54706 | MEDIUM | 4.8 | — | Jul 31, 2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien... |
| CVE-2026-52856 | HIGH | 7.5 | — | Jul 31, 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a ... |
| CVE-2026-52855 | CRITICAL | 9.9 | — | Jul 31, 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{... |
| CVE-2026-67607 | HIGH | 8.2 | 0.3% | Jul 31, 2026 | LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thr... |
| CVE-2026-59232 | MEDIUM | 5.3 | — | Jul 31, 2026 | Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding ... |
| CVE-2026-59231 | MEDIUM | 5.3 | — | Jul 31, 2026 | Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to... |
| CVE-2026-56571 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions... |
| CVE-2026-56570 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Va... |
| CVE-2026-56569 | LOW | 3.3 | 0.1% | Jul 31, 2026 | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config... |
| CVE-2026-56568 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It inv... |
| CVE-2026-56567 | LOW | 3.3 | 0.1% | Jul 31, 2026 | HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern... |
| CVE-2026-52857 | MEDIUM | 5.5 | — | Jul 31, 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, un... |
| CVE-2026-18141 | HIGH | 8.2 | 0.3% | Jul 31, 2026 | A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthentic... |
| CVE-2026-17566 | CRITICAL | 9.9 | 0.4% | Jul 31, 2026 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query in... |
| CVE-2026-17351 | CRITICAL | 9 | 0.4% | Jul 31, 2026 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu... |
| CVE-2026-17350 | MEDIUM | 5.4 | 0.2% | Jul 31, 2026 | The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce... |
| CVE-2026-17349 | CRITICAL | 9.6 | 0.3% | Jul 31, 2026 | /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of ... |
| CVE-2026-17348 | MEDIUM | 6.9 | 0.2% | Jul 31, 2026 | In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's bef... |
| CVE-2026-17347 | HIGH | 8.8 | 0.3% | Jul 31, 2026 | The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that ... |
| CVE-2026-17346 | HIGH | 8.8 | 0.4% | Jul 31, 2026 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatin... |
| CVE-2026-16504 | CRITICAL | 9.8 | 0.1% | Jul 31, 2026 | Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database passw... |
| CVE-2026-16503 | CRITICAL | 9.1 | 0.1% | Jul 31, 2026 | Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces ... |
| CVE-2026-10686 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now