2026 CVE Vulnerabilities
57,045 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54769 | CRITICAL | 10 | 0.9% | Jul 10, 2026 | Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable ... |
| CVE-2026-54760 | CRITICAL | 9.3 | 0.6% | Jul 10, 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAge... |
| CVE-2026-50181 | HIGH | 7.1 | 0.2% | Jul 10, 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `Rea... |
| CVE-2026-50180 | HIGH | 8.7 | 0.7% | Jul 10, 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` ... |
| CVE-2026-15317 | MEDIUM | 6.3 | 0.2% | Jul 10, 2026 | A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFe... |
| CVE-2026-15311 | LOW | 3.5 | 0.2% | Jul 10, 2026 | A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function Ma... |
| CVE-2026-12598 | HIGH | 8.1 | 0.3% | Jul 10, 2026 | The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via... |
| CVE-2026-12597 | HIGH | 8.1 | 0.4% | Jul 10, 2026 | The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions... |
| CVE-2026-12595 | HIGH | 8.1 | 0.3% | Jul 10, 2026 | The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all version... |
| CVE-2026-59858 | HIGH | 7.8 | 0.1% | Jul 9, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/cco... |
| CVE-2026-59857 | MEDIUM | 5.5 | 0.1% | Jul 9, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in s... |
| CVE-2026-59856 | HIGH | 7.8 | 0.2% | Jul 9, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/p... |
| CVE-2026-59855 | HIGH | 8.6 | 0.3% | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts in... |
| CVE-2026-59854 | MEDIUM | 4.9 | 0.3% | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts at... |
| CVE-2026-59853 | MEDIUM | 6.5 | 0.2% | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint ret... |
| CVE-2026-59834 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/searc... |
| CVE-2026-59833 | HIGH | 8.6 | 0.4% | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content t... |
| CVE-2026-59832 | HIGH | 7.7 | 0.3% | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler ser... |
| CVE-2026-59831 | MEDIUM | 4.4 | 0.2% | Jul 9, 2026 | GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace ... |
| CVE-2026-57501 | NONE | 0 | 0.3% | Jul 9, 2026 | Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance ... |
| CVE-2026-44342 | MEDIUM | 5.3 | 0.2% | Jul 9, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0... |
| CVE-2026-33655 | HIGH | 7.7 | 0.4% | Jul 9, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0... |
| CVE-2026-59828 | MEDIUM | 5.3 | 0.3% | Jul 9, 2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions tha... |
| CVE-2026-58144 | MEDIUM | 5.4 | 0.1% | Jul 9, 2026 | Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users wi... |
| CVE-2026-58143 | HIGH | 8.8 | 0.2% | Jul 9, 2026 | Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attacke... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now