2026 CVE Vulnerabilities
56,900 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44583 | MEDIUM | 5.3 | 0.4% | Jul 20, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the... |
| CVE-2026-44509 | — | — | 0.1% | Jul 20, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a ... |
| CVE-2026-44508 | — | — | 0.3% | Jul 20, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a ... |
| CVE-2026-44507 | — | — | 0.1% | Jul 20, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43617. Reason: This candidate is a ... |
| CVE-2026-13381 | HIGH | 8.1 | 0.2% | Jul 20, 2026 | VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/fil... |
| CVE-2026-13380 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent... |
| CVE-2026-63767 | CRITICAL | 9.8 | 0.7% | Jul 20, 2026 | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability t... |
| CVE-2026-63766 | CRITICAL | 9.8 | 1.4% | Jul 20, 2026 | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, a... |
| CVE-2026-53593 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylis... |
| CVE-2026-53592 | MEDIUM | 4.6 | 0.1% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in th... |
| CVE-2026-53591 | HIGH | 8.6 | 0.2% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthen... |
| CVE-2026-44231 | CRITICAL | 9.1 | 0.2% | Jul 20, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prio... |
| CVE-2026-44230 | MEDIUM | 6.1 | 0.2% | Jul 20, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10... |
| CVE-2026-44229 | MEDIUM | 5.4 | 0.1% | Jul 20, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to bo... |
| CVE-2026-16337 | CRITICAL | 9.4 | 0.4% | Jul 20, 2026 | Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-... |
| CVE-2026-15788 | HIGH | 7.5 | 0.1% | Jul 20, 2026 | BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory ju... |
| CVE-2026-64619 | HIGH | 8.7 | 0.2% | Jul 20, 2026 | FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated a... |
| CVE-2026-64194 | HIGH | 7.5 | 0.4% | Jul 20, 2026 | Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::Doma... |
| CVE-2026-64193 | CRITICAL | 9.8 | 0.4% | Jul 20, 2026 | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EX... |
| CVE-2026-63771 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by ... |
| CVE-2026-63770 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthentic... |
| CVE-2026-63769 | HIGH | 7.7 | 0.2% | Jul 20, 2026 | Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport... |
| CVE-2026-63768 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows at... |
| CVE-2026-63731 | HIGH | 7.7 | 0.2% | Jul 20, 2026 | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir... |
| CVE-2026-63730 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now