2026 CVE Vulnerabilities
57,021 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56668 | HIGH | 8.1 | 0.2% | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for ur... |
| CVE-2026-56667 | HIGH | 7.3 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPreconditi... |
| CVE-2026-56666 | MEDIUM | 4.8 | 0.2% | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch... |
| CVE-2026-56665 | MEDIUM | 4.2 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity m... |
| CVE-2026-56664 | MEDIUM | 4.2 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov... |
| CVE-2026-55672 | HIGH | 7.4 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchan... |
| CVE-2026-55671 | LOW | 2.3 | 0.3% | Jul 10, 2026 | ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification chan... |
| CVE-2026-55670 | LOW | 2.3 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the... |
| CVE-2026-53780 | — | — | — | Jul 10, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-2397 | CRITICAL | 9.8 | — | Jul 10, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automa... |
| CVE-2026-59193 | MEDIUM | 4.9 | — | Jul 10, 2026 | Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by ... |
| CVE-2026-59190 | HIGH | 8.7 | — | Jul 10, 2026 | grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.5... |
| CVE-2026-59180 | LOW | 3.1 | — | Jul 10, 2026 | Apprise is an open source library which allows you to send a notification to almost all of the most popular notification... |
| CVE-2026-59162 | HIGH | 7.5 | 0.5% | Jul 10, 2026 | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses... |
| CVE-2026-59161 | HIGH | 7.5 | 0.5% | Jul 10, 2026 | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming w... |
| CVE-2026-59154 | MEDIUM | 4.3 | — | Jul 10, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct... |
| CVE-2026-58493 | MEDIUM | 5.1 | 0.3% | Jul 10, 2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by dir... |
| CVE-2026-58492 | CRITICAL | 9.2 | — | Jul 10, 2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its t... |
| CVE-2026-57167 | MEDIUM | 5.1 | — | Jul 10, 2026 | PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages em... |
| CVE-2026-56675 | HIGH | 8.3 | — | Jul 10, 2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* acce... |
| CVE-2026-55890 | MEDIUM | 4.8 | — | Jul 10, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media ... |
| CVE-2026-55885 | MEDIUM | 6.8 | 0.2% | Jul 10, 2026 | Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download ... |
| CVE-2026-55783 | LOW | 2.4 | — | Jul 10, 2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-hous... |
| CVE-2026-55782 | LOW | 2.4 | 0.1% | Jul 10, 2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly a... |
| CVE-2026-55781 | LOW | 2.4 | — | Jul 10, 2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now