2026 CVE Vulnerabilities

56,900 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63108HIGH8.8Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attac...
CVE-2026-63107HIGH7.7LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey templat...
CVE-2026-62414CRITICAL9.1Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder ...
CVE-2026-61901MEDIUM6.1Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an ...
CVE-2026-61900CRITICAL10Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla exten...
CVE-2026-61425CRITICAL9.4Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable a...
CVE-2026-61424CRITICAL10Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla ext...
CVE-2026-60034CRITICAL9.4Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia i...
CVE-2026-60033MEDIUM5.1Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia i...
CVE-2026-60032CRITICAL9.4Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia ...
CVE-2026-60031MEDIUM6.9Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page...
CVE-2026-60030HIGH8.7Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla...
CVE-2026-60029MEDIUM5.1Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Pa...
CVE-2026-60028HIGH8.6Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Pa...
CVE-2026-60027HIGH8.7Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla...
CVE-2026-60026HIGH8.9Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension...
CVE-2026-48389HIGH7.8DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in...
CVE-2026-12341CRITICAL9.8This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to prot...
CVE-2026-8170HIGH8.7The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize pat...
CVE-2026-8169HIGH8.7ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The cha...
CVE-2026-64612HIGH7.5A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without inst...
CVE-2026-55639MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Se...
CVE-2026-55626HIGH7.3xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using...
CVE-2026-48812HIGH7.5FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's...
CVE-2026-46715MEDIUM5.3Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentica...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now