2026 CVE Vulnerabilities
56,900 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51031 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T... |
| CVE-2026-51025 | MEDIUM | 6.1 | 0.2% | Jul 20, 2026 | Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary... |
| CVE-2026-47255 | HIGH | 8.2 | 0.2% | Jul 20, 2026 | AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenti... |
| CVE-2026-47144 | MEDIUM | 5.5 | 0.1% | Jul 20, 2026 | Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame... |
| CVE-2026-47134 | MEDIUM | 6.9 | 0.1% | Jul 20, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private k... |
| CVE-2026-47133 | MEDIUM | 6.9 | 0.1% | Jul 20, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.... |
| CVE-2026-47128 | MEDIUM | 6.1 | 0.1% | Jul 20, 2026 | nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landloc... |
| CVE-2026-44510 | — | — | 0.2% | Jul 20, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a ... |
| CVE-2026-16324 | HIGH | 7.3 | 0.3% | Jul 20, 2026 | A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function ... |
| CVE-2026-12900 | MEDIUM | 6.4 | 0.2% | Jul 20, 2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-64651 | MEDIUM | 6.3 | 0.1% | Jul 20, 2026 | The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.2... |
| CVE-2026-64650 | MEDIUM | 6.3 | 0.1% | Jul 20, 2026 | The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command ... |
| CVE-2026-58624 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server... |
| CVE-2026-56624 | HIGH | 7.3 | 0.2% | Jul 20, 2026 | Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side an... |
| CVE-2026-56623 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and... |
| CVE-2026-56452 | HIGH | 7.5 | 0.4% | Jul 20, 2026 | Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and ser... |
| CVE-2026-55219 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the... |
| CVE-2026-53596 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeSco... |
| CVE-2026-53595 | CRITICAL | 9.4 | 0.3% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public ... |
| CVE-2026-53594 | MEDIUM | 4.9 | 0.4% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Lo... |
| CVE-2026-47198 | HIGH | 8.5 | 0.4% | Jul 20, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the... |
| CVE-2026-47130 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Le... |
| CVE-2026-47129 | HIGH | 8.1 | 0.2% | Jul 20, 2026 | NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Co... |
| CVE-2026-44585 | MEDIUM | 5.4 | 0.3% | Jul 20, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the... |
| CVE-2026-44584 | MEDIUM | 4.3 | 0.2% | Jul 20, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now