2026 CVE Vulnerabilities

56,936 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45713HIGH7.5Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.M...
CVE-2026-45712MEDIUM5.9Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?dat...
CVE-2026-45711HIGH8.2Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <ou...
CVE-2026-45709MEDIUM5.8Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side R...
CVE-2026-35198CRITICAL9HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i...
CVE-2026-32822MEDIUM6.1dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32807HIGH7.5dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-28220CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i...
CVE-2026-27823HIGH8.7A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an auth...
CVE-2026-26199MEDIUM6.5HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name`...
CVE-2026-26197HIGH7.5HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is cor...
CVE-2026-26081MEDIUM4.8HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise...
CVE-2026-26080LOW3.7HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAPro...
CVE-2026-25039HIGH8.8Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanit...
CVE-2026-21824HIGH8.8HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user perso...
CVE-2026-13724MEDIUM4.3Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an...
CVE-2026-63091HIGH7.1ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-r...
CVE-2026-63090HIGH8.8ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allo...
CVE-2026-63071CRITICAL9.8Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements...
CVE-2026-62418HIGH8.1Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Reso...
CVE-2026-62183CRITICAL9.8Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configure...
CVE-2026-59238MEDIUM6.9Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderA...
CVE-2026-57308CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. A...
CVE-2026-54910HIGH7.7FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` ...
CVE-2026-54685MEDIUM5.3FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now