2026 CVE Vulnerabilities
57,052 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23560 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23559 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23556 | CRITICAL | 9.4 | — | Jul 9, 2026 | When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ... |
| CVE-2026-15189 | MEDIUM | 6.3 | 0.4% | Jul 9, 2026 | A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23.... |
| CVE-2026-15188 | MEDIUM | 6.3 | — | Jul 9, 2026 | A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affect... |
| CVE-2026-15187 | MEDIUM | 4.3 | 0.4% | Jul 9, 2026 | A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Publ... |
| CVE-2026-11404 | HIGH | 7.5 | 0.6% | Jul 9, 2026 | Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello... |
| CVE-2026-60109 | HIGH | 8.7 | 0.5% | Jul 9, 2026 | Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauth... |
| CVE-2026-60108 | HIGH | 8.7 | 0.4% | Jul 9, 2026 | Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthentica... |
| CVE-2026-5005 | MEDIUM | 5.4 | — | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics... |
| CVE-2026-56292 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing... |
| CVE-2026-54801 | HIGH | 8.6 | — | Jul 9, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst... |
| CVE-2026-54800 | MEDIUM | 6.3 | — | Jul 9, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst... |
| CVE-2026-54799 | HIGH | 8.4 | — | Jul 9, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst... |
| CVE-2026-54798 | HIGH | 7.1 | — | Jul 9, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst... |
| CVE-2026-60095 | MEDIUM | 6.9 | 0.5% | Jul 9, 2026 | Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake func... |
| CVE-2026-60094 | MEDIUM | 6.9 | 0.4% | Jul 9, 2026 | Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated ... |
| CVE-2026-4256 | HIGH | 8.2 | — | Jul 9, 2026 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology ... |
| CVE-2026-15186 | MEDIUM | 6.3 | — | Jul 9, 2026 | A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply... |
| CVE-2026-15185 | LOW | 3.3 | — | Jul 9, 2026 | A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools... |
| CVE-2026-14261 | CRITICAL | 9.1 | — | Jul 9, 2026 | A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation ... |
| CVE-2026-12879 | MEDIUM | 5.9 | — | Jul 9, 2026 | An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google... |
| CVE-2026-12593 | HIGH | 8.7 | 0.3% | Jul 9, 2026 | The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to en... |
| CVE-2026-12116 | CRITICAL | 9.8 | — | Jul 9, 2026 | A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings,... |
| CVE-2026-15184 | LOW | 3.3 | — | Jul 9, 2026 | A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now