2026 CVE Vulnerabilities
43,308 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16767 | MEDIUM | 6.5 | 0.5% | Jul 23, 2026 | A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file sr... |
| CVE-2026-16764 | MEDIUM | 6.3 | 0.2% | Jul 23, 2026 | A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file do... |
| CVE-2026-16763 | MEDIUM | 5.3 | 0.7% | Jul 23, 2026 | A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown funct... |
| CVE-2026-39155 | MEDIUM | 6.5 | 0.1% | Jul 23, 2026 | Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name ... |
| CVE-2026-15968 | MEDIUM | 5.4 | 0.2% | Jul 23, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr... |
| CVE-2026-64785 | MEDIUM | 5.3 | 0.1% | Jul 23, 2026 | SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters r... |
| CVE-2026-48013 | MEDIUM | 4.1 | 0.2% | Jul 23, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint ... |
| CVE-2026-48012 | MEDIUM | 4.3 | 0.2% | Jul 23, 2026 | Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO ... |
| CVE-2026-12353 | MEDIUM | 5.3 | 0.3% | Jul 23, 2026 | An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly se... |
| CVE-2026-65010 | MEDIUM | 6.6 | — | Jul 23, 2026 | Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that a... |
| CVE-2026-65920 | MEDIUM | 5.3 | — | Jul 23, 2026 | Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_... |
| CVE-2026-65763 | MEDIUM | 5.1 | — | Jul 23, 2026 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs... |
| CVE-2026-65762 | MEDIUM | 5.1 | — | Jul 23, 2026 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user i... |
| CVE-2026-65699 | MEDIUM | 4.2 | — | Jul 23, 2026 | AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica... |
| CVE-2026-47769 | MEDIUM | 5.3 | — | Jul 23, 2026 | APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr... |
| CVE-2026-47755 | MEDIUM | 6.5 | 0.3% | Jul 23, 2026 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi... |
| CVE-2026-65698 | MEDIUM | 6 | 0.3% | Jul 23, 2026 | Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace... |
| CVE-2026-65697 | MEDIUM | 6.1 | — | Jul 23, 2026 | Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that... |
| CVE-2026-65696 | MEDIUM | 5.4 | — | Jul 23, 2026 | Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip... |
| CVE-2026-16768 | MEDIUM | 5.3 | 0.2% | Jul 23, 2026 | A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale... |
| CVE-2026-48539 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf... |
| CVE-2026-48538 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat... |
| CVE-2026-48537 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati... |
| CVE-2026-48536 | MEDIUM | 5.4 | — | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio... |
| CVE-2026-48535 | MEDIUM | 5.4 | 0.1% | Jul 23, 2026 | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configurati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now