2026 CVE Vulnerabilities
56,900 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63108 | HIGH | 8.8 | 1.9% | Jul 20, 2026 | Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attac... |
| CVE-2026-63107 | HIGH | 7.7 | 0.2% | Jul 20, 2026 | LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey templat... |
| CVE-2026-62414 | CRITICAL | 9.1 | 0.2% | Jul 20, 2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder ... |
| CVE-2026-61901 | MEDIUM | 6.1 | 0.1% | Jul 20, 2026 | Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an ... |
| CVE-2026-61900 | CRITICAL | 10 | 0.3% | Jul 20, 2026 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla exten... |
| CVE-2026-61425 | CRITICAL | 9.4 | 0.3% | Jul 20, 2026 | Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable a... |
| CVE-2026-61424 | CRITICAL | 10 | 0.3% | Jul 20, 2026 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla ext... |
| CVE-2026-60034 | CRITICAL | 9.4 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia i... |
| CVE-2026-60033 | MEDIUM | 5.1 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia i... |
| CVE-2026-60032 | CRITICAL | 9.4 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia ... |
| CVE-2026-60031 | MEDIUM | 6.9 | 0.3% | Jul 20, 2026 | Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page... |
| CVE-2026-60030 | HIGH | 8.7 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla... |
| CVE-2026-60029 | MEDIUM | 5.1 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Pa... |
| CVE-2026-60028 | HIGH | 8.6 | 0.2% | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Pa... |
| CVE-2026-60027 | HIGH | 8.7 | 0.3% | Jul 20, 2026 | Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla... |
| CVE-2026-60026 | HIGH | 8.9 | 0.3% | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension... |
| CVE-2026-48389 | HIGH | 7.8 | 0.3% | Jul 20, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in... |
| CVE-2026-12341 | CRITICAL | 9.8 | 0.2% | Jul 20, 2026 | This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to prot... |
| CVE-2026-8170 | HIGH | 8.7 | 0.4% | Jul 20, 2026 | The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize pat... |
| CVE-2026-8169 | HIGH | 8.7 | 0.3% | Jul 20, 2026 | ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The cha... |
| CVE-2026-64612 | HIGH | 7.5 | 0.4% | Jul 20, 2026 | A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without inst... |
| CVE-2026-55639 | MEDIUM | 5.3 | 0.3% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Se... |
| CVE-2026-55626 | HIGH | 7.3 | 0.1% | Jul 20, 2026 | xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using... |
| CVE-2026-48812 | HIGH | 7.5 | 0.4% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's... |
| CVE-2026-46715 | MEDIUM | 5.3 | 0.3% | Jul 20, 2026 | Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentica... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now