2026 CVE Vulnerabilities
57,013 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61875 | HIGH | 8.8 | 0.3% | Jul 12, 2026 | luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject Jav... |
| CVE-2026-61874 | LOW | 3.1 | 0.2% | Jul 12, 2026 | filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, all... |
| CVE-2026-59260 | HIGH | 8.8 | 0.7% | Jul 12, 2026 | OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users t... |
| CVE-2026-56336 | MEDIUM | 6.9 | 0.2% | Jul 12, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain ... |
| CVE-2026-56313 | HIGH | 8.1 | 0.3% | Jul 12, 2026 | Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that al... |
| CVE-2026-56308 | HIGH | 8.4 | 0.2% | Jul 12, 2026 | Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification ... |
| CVE-2026-56281 | MEDIUM | 5.1 | 0.2% | Jul 12, 2026 | Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit p... |
| CVE-2026-56271 | CRITICAL | 9.8 | 0.4% | Jul 12, 2026 | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refr... |
| CVE-2026-56260 | CRITICAL | 9.1 | 0.4% | Jul 12, 2026 | Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf end... |
| CVE-2026-56259 | HIGH | 8.8 | 0.3% | Jul 12, 2026 | Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to ... |
| CVE-2026-56252 | MEDIUM | 5.4 | 0.2% | Jul 12, 2026 | Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scope... |
| CVE-2026-56241 | HIGH | 8.3 | 0.2% | Jul 12, 2026 | Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to del... |
| CVE-2026-56238 | HIGH | 8.7 | 0.4% | Jul 12, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint t... |
| CVE-2026-15500 | MEDIUM | 6.3 | 0.2% | Jul 12, 2026 | A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2. Affected by this vulnerability is the function get_o... |
| CVE-2026-15499 | MEDIUM | 6.3 | 0.2% | Jul 12, 2026 | A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function FutureTaskTool.call of... |
| CVE-2026-15498 | HIGH | 7.3 | 0.3% | Jul 12, 2026 | A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. This impact... |
| CVE-2026-15497 | HIGH | 7.3 | 0.4% | Jul 12, 2026 | A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file so... |
| CVE-2026-15496 | MEDIUM | 6.3 | 1.2% | Jul 12, 2026 | A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of... |
| CVE-2026-15495 | MEDIUM | 6.3 | 1.5% | Jul 12, 2026 | A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of ... |
| CVE-2026-15494 | MEDIUM | 4.7 | 0.2% | Jul 12, 2026 | A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/... |
| CVE-2026-15493 | MEDIUM | 5.1 | 0.2% | Jul 12, 2026 | A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. Thi... |
| CVE-2026-15492 | MEDIUM | 4.3 | 0.4% | Jul 12, 2026 | A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c649e8086d6. This vulne... |
| CVE-2026-15491 | HIGH | 7.3 | 0.6% | Jul 12, 2026 | A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects ... |
| CVE-2026-15490 | HIGH | 7.3 | 0.4% | Jul 12, 2026 | A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected... |
| CVE-2026-15489 | HIGH | 7.3 | 0.3% | Jul 12, 2026 | A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now