2026 CVE Vulnerabilities
56,936 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45713 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.M... |
| CVE-2026-45712 | MEDIUM | 5.9 | 0.2% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?dat... |
| CVE-2026-45711 | HIGH | 8.2 | 0.2% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <ou... |
| CVE-2026-45709 | MEDIUM | 5.8 | 0.2% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side R... |
| CVE-2026-35198 | CRITICAL | 9 | 0.2% | Jul 20, 2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability i... |
| CVE-2026-32822 | MEDIUM | 6.1 | 0.2% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-32807 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-28220 | CRITICAL | 9.1 | 0.2% | Jul 20, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i... |
| CVE-2026-27823 | HIGH | 8.7 | 1.0% | Jul 20, 2026 | A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an auth... |
| CVE-2026-26199 | MEDIUM | 6.5 | 0.3% | Jul 20, 2026 | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name`... |
| CVE-2026-26197 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is cor... |
| CVE-2026-26081 | MEDIUM | 4.8 | 0.5% | Jul 20, 2026 | HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise... |
| CVE-2026-26080 | LOW | 3.7 | 0.5% | Jul 20, 2026 | HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAPro... |
| CVE-2026-25039 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanit... |
| CVE-2026-21824 | HIGH | 8.8 | 0.2% | Jul 20, 2026 | HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user perso... |
| CVE-2026-13724 | MEDIUM | 4.3 | 0.2% | Jul 20, 2026 | Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an... |
| CVE-2026-63091 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-r... |
| CVE-2026-63090 | HIGH | 8.8 | 0.5% | Jul 20, 2026 | ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allo... |
| CVE-2026-63071 | CRITICAL | 9.8 | 0.4% | Jul 20, 2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements... |
| CVE-2026-62418 | HIGH | 8.1 | 0.2% | Jul 20, 2026 | Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Reso... |
| CVE-2026-62183 | CRITICAL | 9.8 | 0.3% | Jul 20, 2026 | Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configure... |
| CVE-2026-59238 | MEDIUM | 6.9 | 0.3% | Jul 20, 2026 | Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderA... |
| CVE-2026-57308 | CRITICAL | 9.8 | 0.4% | Jul 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. A... |
| CVE-2026-54910 | HIGH | 7.7 | 0.3% | Jul 20, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` ... |
| CVE-2026-54685 | MEDIUM | 5.3 | 0.3% | Jul 20, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now