2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18321 | MEDIUM | 4.7 | — | Jul 31, 2026 | Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd |
| CVE-2026-34497 | MEDIUM | 5.4 | 0.4% | Jul 31, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste... |
| CVE-2026-34495 | MEDIUM | 5.4 | 0.4% | Jul 31, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F... |
| CVE-2026-34490 | MEDIUM | 5.5 | 0.1% | Jul 31, 2026 | Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac... |
| CVE-2026-58047 | MEDIUM | 5.6 | 0.5% | Jul 31, 2026 | HTTP Smuggling in cPanel allows potential leak of credentials. |
| CVE-2026-54707 | MEDIUM | 5.4 | — | Jul 31, 2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien... |
| CVE-2026-54706 | MEDIUM | 4.8 | — | Jul 31, 2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien... |
| CVE-2026-59232 | MEDIUM | 5.3 | — | Jul 31, 2026 | Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding ... |
| CVE-2026-59231 | MEDIUM | 5.3 | — | Jul 31, 2026 | Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to... |
| CVE-2026-56571 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions... |
| CVE-2026-56570 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Va... |
| CVE-2026-56568 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It inv... |
| CVE-2026-52857 | MEDIUM | 5.5 | — | Jul 31, 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, un... |
| CVE-2026-17350 | MEDIUM | 5.4 | 0.2% | Jul 31, 2026 | The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce... |
| CVE-2026-17348 | MEDIUM | 6.9 | 0.2% | Jul 31, 2026 | In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's bef... |
| CVE-2026-67350 | MEDIUM | 4.3 | — | Jul 31, 2026 | Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to re... |
| CVE-2026-28145 | MEDIUM | 5.3 | 0.1% | Jul 31, 2026 | Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User ... |
| CVE-2026-28144 | MEDIUM | 4.3 | 0.2% | Jul 31, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensiti... |
| CVE-2026-15227 | MEDIUM | 5.3 | — | Jul 31, 2026 | Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking t... |
| CVE-2026-46594 | MEDIUM | 5.1 | — | Jul 31, 2026 | A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicio... |
| CVE-2026-64607 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma... |
| CVE-2026-44615 | MEDIUM | 6.5 | 0.5% | Jul 31, 2026 | Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi... |
| CVE-2026-17567 | MEDIUM | 5.3 | 0.4% | Jul 31, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2026-18437 | MEDIUM | 5.3 | 0.3% | Jul 31, 2026 | The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access ... |
| CVE-2026-18436 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now