2026 CVE Vulnerabilities
57,011 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15517 | HIGH | 7.3 | 0.3% | Jul 13, 2026 | A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSumma... |
| CVE-2026-15516 | MEDIUM | 5.6 | 0.3% | Jul 13, 2026 | A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/... |
| CVE-2026-15515 | HIGH | 7 | 0.1% | Jul 13, 2026 | A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown process... |
| CVE-2026-15514 | HIGH | 7.3 | 0.3% | Jul 13, 2026 | A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This vulnerability affects the function RPCS... |
| CVE-2026-15513 | MEDIUM | 6.3 | 1.4% | Jul 13, 2026 | A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uci_set_value of the f... |
| CVE-2026-15512 | MEDIUM | 6.3 | 0.4% | Jul 13, 2026 | A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown functionality of the ... |
| CVE-2026-15511 | CRITICAL | 9.8 | 2.7% | Jul 12, 2026 | A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function sy... |
| CVE-2026-15510 | MEDIUM | 6.3 | 0.3% | Jul 12, 2026 | A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. T... |
| CVE-2026-15509 | MEDIUM | 6.3 | 0.3% | Jul 12, 2026 | A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON... |
| CVE-2026-15508 | MEDIUM | 6.3 | 0.3% | Jul 12, 2026 | A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file... |
| CVE-2026-15507 | MEDIUM | 6.3 | 0.3% | Jul 12, 2026 | A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file ... |
| CVE-2026-15506 | HIGH | 7.8 | 0.2% | Jul 12, 2026 | A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown func... |
| CVE-2026-15505 | LOW | 3.5 | 0.2% | Jul 12, 2026 | A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra... |
| CVE-2026-10668 | MEDIUM | 4.6 | 0.1% | Jul 12, 2026 | The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data IN stage ... |
| CVE-2026-10667 | HIGH | 7.8 | 0.1% | Jul 12, 2026 | Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-l... |
| CVE-2026-10666 | CRITICAL | 9.8 | 0.3% | Jul 12, 2026 | parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the... |
| CVE-2026-10665 | HIGH | 7.4 | 0.4% | Jul 12, 2026 | In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbou... |
| CVE-2026-10664 | MEDIUM | 5 | 0.1% | Jul 12, 2026 | The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nrf_wifi/src... |
| CVE-2026-10663 | MEDIUM | 6.1 | 0.2% | Jul 12, 2026 | In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c... |
| CVE-2026-58596 | HIGH | 8.3 | 0.5% | Jul 12, 2026 | Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges o... |
| CVE-2026-15502 | MEDIUM | 6.3 | 0.2% | Jul 12, 2026 | A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php o... |
| CVE-2026-15501 | MEDIUM | 6.3 | 0.2% | Jul 12, 2026 | A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function T... |
| CVE-2026-61876 | CRITICAL | 9.4 | 0.2% | Jul 12, 2026 | LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent networ... |
| CVE-2026-61875 | HIGH | 8.8 | 0.3% | Jul 12, 2026 | luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject Jav... |
| CVE-2026-61874 | LOW | 3.1 | 0.2% | Jul 12, 2026 | filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, all... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now