2026 CVE Vulnerabilities
56,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49971 | MEDIUM | 6.1 | 0.2% | Jul 13, 2026 | Laravel-Mediable before 7.0.0 contains a stored cross-site scripting vulnerability that allows authenticated or anonymou... |
| CVE-2026-49970 | HIGH | 8.8 | 0.8% | Jul 13, 2026 | Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows a... |
| CVE-2026-49969 | HIGH | 7.4 | 0.2% | Jul 13, 2026 | Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue... |
| CVE-2026-26396 | HIGH | 7.5 | — | Jul 13, 2026 | OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/applicati... |
| CVE-2026-14906 | MEDIUM | 5.3 | 0.2% | Jul 13, 2026 | Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within t... |
| CVE-2026-61505 | MEDIUM | 6.9 | 0.5% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthentica... |
| CVE-2026-61504 | MEDIUM | 5.4 | 0.2% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be ... |
| CVE-2026-61503 | MEDIUM | 6.9 | 0.3% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the ... |
| CVE-2026-61502 | MEDIUM | 5.1 | 0.2% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its... |
| CVE-2026-61501 | MEDIUM | 6.1 | 0.3% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote u... |
| CVE-2026-61500 | CRITICAL | 9.8 | 0.7% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generato... |
| CVE-2026-61463 | HIGH | 8.8 | — | Jul 13, 2026 | Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to m... |
| CVE-2026-61462 | CRITICAL | 9.2 | — | Jul 13, 2026 | mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to re... |
| CVE-2026-60103 | MEDIUM | 6.8 | 0.1% | Jul 13, 2026 | Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or rea... |
| CVE-2026-53365 | MEDIUM | 5.5 | 0.1% | Jul 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb... |
| CVE-2026-53364 | MEDIUM | 5.5 | 0.1% | Jul 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_... |
| CVE-2026-57433 | CRITICAL | 9.8 | 0.2% | Jul 13, 2026 | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retr... |
| CVE-2026-57432 | HIGH | 8.4 | 0.2% | Jul 13, 2026 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S... |
| CVE-2026-13221 | CRITICAL | 9.1 | 0.4% | Jul 13, 2026 | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect re... |
| CVE-2026-61692 | — | — | — | Jul 13, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61454. Reason: This candidate is a ... |
| CVE-2026-59245 | HIGH | 8.1 | 0.4% | Jul 13, 2026 | In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission reso... |
| CVE-2026-58065 | HIGH | 8.1 | 0.5% | Jul 13, 2026 | The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling S... |
| CVE-2026-6847 | CRITICAL | 9.3 | 0.6% | Jul 13, 2026 | Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload fu... |
| CVE-2026-61498 | CRITICAL | 9.8 | 2.2% | Jul 13, 2026 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php en... |
| CVE-2026-60121 | CRITICAL | 9.8 | 1.4% | Jul 13, 2026 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now