2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-60034 | CRITICAL | 9.4 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia i... |
| CVE-2026-60032 | CRITICAL | 9.4 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia ... |
| CVE-2026-12341 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to prot... |
| CVE-2026-39878 | CRITICAL | 9.3 | 0.2% | Jul 20, 2026 | Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration fo... |
| CVE-2026-54051 | CRITICAL | 9.9 | 0.4% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell comma... |
| CVE-2026-41521 | CRITICAL | 9.1 | 0.6% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing s... |
| CVE-2026-41252 | CRITICAL | 9.8 | 1.1% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap... |
| CVE-2026-35048 | CRITICAL | 9.8 | 0.3% | Jul 20, 2026 | The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them d... |
| CVE-2026-51027 | CRITICAL | 9.9 | 0.3% | Jul 20, 2026 | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. |
| CVE-2026-46428 | CRITICAL | 9.1 | 0.2% | Jul 20, 2026 | lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug ... |
| CVE-2026-46412 | CRITICAL | 10 | 0.4% | Jul 20, 2026 | @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support... |
| CVE-2026-35198 | CRITICAL | 9 | 0.2% | Jul 20, 2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i... |
| CVE-2026-28220 | CRITICAL | 9.1 | 0.2% | Jul 20, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i... |
| CVE-2026-63071 | CRITICAL | 9.8 | 0.4% | Jul 20, 2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements... |
| CVE-2026-62183 | CRITICAL | 9.8 | 0.3% | Jul 20, 2026 | Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configure... |
| CVE-2026-57308 | CRITICAL | 9.8 | 0.4% | Jul 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. A... |
| CVE-2026-53421 | CRITICAL | 9.8 | 0.5% | Jul 20, 2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlemen... |
| CVE-2026-53405 | CRITICAL | 9.8 | 0.3% | Jul 20, 2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements... |
| CVE-2026-12701 | CRITICAL | 9 | — | Jul 20, 2026 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content pa... |
| CVE-2026-57309 | CRITICAL | 9.3 | 0.3% | Jul 20, 2026 | A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to injec... |
| CVE-2026-64622 | CRITICAL | 9.3 | 0.4% | Jul 20, 2026 | Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/... |
| CVE-2026-64621 | CRITICAL | 9.3 | 0.2% | Jul 20, 2026 | FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_appl... |
| CVE-2026-64620 | CRITICAL | 9.1 | 0.6% | Jul 20, 2026 | FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypt... |
| CVE-2026-63756 | CRITICAL | 9.2 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows... |
| CVE-2026-16242 | CRITICAL | 9.4 | 0.7% | Jul 20, 2026 | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now