2026 CVE Vulnerabilities

56,900 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-51031HIGH7.5FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T...
CVE-2026-51025MEDIUM6.1Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary...
CVE-2026-47255HIGH8.2AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenti...
CVE-2026-47144MEDIUM5.5Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame...
CVE-2026-47134MEDIUM6.9ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private k...
CVE-2026-47133MEDIUM6.9ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5....
CVE-2026-47128MEDIUM6.1nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landloc...
CVE-2026-44510Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a ...
CVE-2026-16324HIGH7.3A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function ...
CVE-2026-12900MEDIUM6.4The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-64651MEDIUM6.3The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.2...
CVE-2026-64650MEDIUM6.3The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command ...
CVE-2026-58624MEDIUM5.4Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server...
CVE-2026-56624HIGH7.3Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side an...
CVE-2026-56623HIGH7.1Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and...
CVE-2026-56452HIGH7.5Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and ser...
CVE-2026-55219MEDIUM5.3Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the...
CVE-2026-53596MEDIUM5.3FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeSco...
CVE-2026-53595CRITICAL9.4FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public ...
CVE-2026-53594MEDIUM4.9FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Lo...
CVE-2026-47198HIGH8.5Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the...
CVE-2026-47130HIGH7.1NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Le...
CVE-2026-47129HIGH8.1NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Co...
CVE-2026-44585MEDIUM5.4Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the...
CVE-2026-44584MEDIUM4.3Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now