2026 CVE Vulnerabilities
57,052 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50188 | MEDIUM | 6.9 | 0.3% | Jul 9, 2026 | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Htt... |
| CVE-2026-49276 | HIGH | 7.4 | 0.3% | Jul 9, 2026 | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any b... |
| CVE-2026-49274 | MEDIUM | 5.3 | 0.3% | Jul 9, 2026 | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with role... |
| CVE-2026-13492 | HIGH | 8.8 | 0.5% | Jul 9, 2026 | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This... |
| CVE-2026-0287 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with... |
| CVE-2026-0286 | HIGH | 7.2 | 1.0% | Jul 9, 2026 | A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticate... |
| CVE-2026-0285 | MEDIUM | 4.9 | 0.2% | Jul 9, 2026 | A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated admini... |
| CVE-2026-0284 | CRITICAL | 9.9 | 0.3% | Jul 9, 2026 | An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enabl... |
| CVE-2026-0283 | HIGH | 7.2 | 0.2% | Jul 9, 2026 | An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software a... |
| CVE-2026-0282 | MEDIUM | 6.5 | 0.2% | Jul 9, 2026 | A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network ac... |
| CVE-2026-0281 | HIGH | 7.1 | 0.2% | Jul 9, 2026 | An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with ... |
| CVE-2026-0280 | HIGH | 7.2 | 0.2% | Jul 9, 2026 | An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticat... |
| CVE-2026-0279 | MEDIUM | 6.1 | 0.3% | Jul 9, 2026 | Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, Global... |
| CVE-2026-61344 | MEDIUM | 6.9 | 0.3% | Jul 9, 2026 | The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that ... |
| CVE-2026-61343 | HIGH | 8.6 | 0.8% | Jul 9, 2026 | LibreBooking's email template editor save action passes the submitted template name directly into the destination file p... |
| CVE-2026-59827 | HIGH | 8.8 | 0.4% | Jul 9, 2026 | Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1... |
| CVE-2026-59826 | CRITICAL | 9.1 | 0.4% | Jul 9, 2026 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60... |
| CVE-2026-59817 | MEDIUM | 5.3 | 0.3% | Jul 9, 2026 | Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed a... |
| CVE-2026-59734 | HIGH | 8.8 | — | Jul 9, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-59726 | CRITICAL | 10 | 0.4% | Jul 9, 2026 | Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exp... |
| CVE-2026-59721 | HIGH | 7.2 | 0.5% | Jul 9, 2026 | Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in ad... |
| CVE-2026-59720 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.t... |
| CVE-2026-59221 | HIGH | 7.7 | — | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitiz... |
| CVE-2026-58378 | HIGH | 8.8 | 0.2% | Jul 9, 2026 | Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB a... |
| CVE-2026-55420 | HIGH | 8.1 | 0.3% | Jul 9, 2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now