2026 CVE Vulnerabilities

56,900 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44583MEDIUM5.3Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the...
CVE-2026-44509Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a ...
CVE-2026-44508Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a ...
CVE-2026-44507Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43617. Reason: This candidate is a ...
CVE-2026-13381HIGH8.1VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/fil...
CVE-2026-13380HIGH7.5VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent...
CVE-2026-63767CRITICAL9.8ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability t...
CVE-2026-63766CRITICAL9.8GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, a...
CVE-2026-53593HIGH8.8FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylis...
CVE-2026-53592MEDIUM4.6FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in th...
CVE-2026-53591HIGH8.6FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthen...
CVE-2026-44231CRITICAL9.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prio...
CVE-2026-44230MEDIUM6.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10...
CVE-2026-44229MEDIUM5.4RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to bo...
CVE-2026-16337CRITICAL9.4Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-...
CVE-2026-15788HIGH7.5BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory ju...
CVE-2026-64619HIGH8.7FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated a...
CVE-2026-64194HIGH7.5Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::Doma...
CVE-2026-64193CRITICAL9.8Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EX...
CVE-2026-63771HIGH7.1Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by ...
CVE-2026-63770HIGH7.5Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthentic...
CVE-2026-63769HIGH7.7Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport...
CVE-2026-63768MEDIUM5.3cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows at...
CVE-2026-63731HIGH7.7HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir...
CVE-2026-63730MEDIUM5.3HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now