2026 CVE Vulnerabilities
56,936 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53421 | CRITICAL | 9.8 | 0.5% | Jul 20, 2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlemen... |
| CVE-2026-53405 | CRITICAL | 9.8 | 0.3% | Jul 20, 2026 | Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements... |
| CVE-2026-52349 | HIGH | 7.8 | 0.3% | Jul 20, 2026 | Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local a... |
| CVE-2026-51386 | — | — | — | Jul 20, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-46409. Reason: This record is a reservation duplicate ... |
| CVE-2026-46516 | MEDIUM | 4.8 | 0.3% | Jul 20, 2026 | Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js... |
| CVE-2026-46410 | HIGH | 8.7 | 0.3% | Jul 20, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may le... |
| CVE-2026-45270 | HIGH | 8.7 | 0.2% | Jul 20, 2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module... |
| CVE-2026-45139 | MEDIUM | 6.5 | 0.3% | Jul 20, 2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enfo... |
| CVE-2026-16277 | MEDIUM | 6.5 | 0.3% | Jul 20, 2026 | A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcin... |
| CVE-2026-16252 | HIGH | 7.3 | — | Jul 20, 2026 | A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System ... |
| CVE-2026-12701 | CRITICAL | 9 | — | Jul 20, 2026 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content pa... |
| CVE-2026-57311 | MEDIUM | 5.3 | 0.4% | Jul 20, 2026 | Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP... |
| CVE-2026-57310 | MEDIUM | 6.3 | 0.2% | Jul 20, 2026 | Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker... |
| CVE-2026-57309 | CRITICAL | 9.3 | 0.3% | Jul 20, 2026 | A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to injec... |
| CVE-2026-16248 | HIGH | 8.8 | — | Jul 20, 2026 | A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the ... |
| CVE-2026-16244 | MEDIUM | 6.3 | — | Jul 20, 2026 | A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerabilit... |
| CVE-2026-12080 | HIGH | 7.3 | 0.2% | Jul 20, 2026 | A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-a... |
| CVE-2026-64623 | HIGH | 8.8 | 0.2% | Jul 20, 2026 | Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the... |
| CVE-2026-64622 | CRITICAL | 9.3 | 0.4% | Jul 20, 2026 | Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/... |
| CVE-2026-64621 | CRITICAL | 9.3 | 0.2% | Jul 20, 2026 | FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_appl... |
| CVE-2026-64620 | CRITICAL | 9.1 | 0.6% | Jul 20, 2026 | FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypt... |
| CVE-2026-63763 | HIGH | 8.8 | 0.2% | Jul 20, 2026 | SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileg... |
| CVE-2026-63762 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript... |
| CVE-2026-63761 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES... |
| CVE-2026-63760 | HIGH | 8.7 | 0.4% | Jul 20, 2026 | SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now