2026 CVE Vulnerabilities
57,060 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15111 | HIGH | 7.5 | 0.2% | Jul 8, 2026 | Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engag... |
| CVE-2026-15110 | HIGH | 8.8 | 0.1% | Jul 8, 2026 | Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to instal... |
| CVE-2026-15109 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sens... |
| CVE-2026-15108 | MEDIUM | 4.3 | 0.1% | Jul 8, 2026 | Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to ... |
| CVE-2026-15107 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-15105 | MEDIUM | 6.3 | 0.3% | Jul 8, 2026 | A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the... |
| CVE-2026-5923 | MEDIUM | 6 | 0.1% | Jul 8, 2026 | Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage. |
| CVE-2026-5922 | MEDIUM | 5.9 | 0.2% | Jul 8, 2026 | The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpa... |
| CVE-2026-55878 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install ... |
| CVE-2026-55877 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() T... |
| CVE-2026-55849 | HIGH | 8.5 | 0.2% | Jul 8, 2026 | @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CL... |
| CVE-2026-55830 | HIGH | 8.3 | 0.2% | Jul 8, 2026 | RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input ... |
| CVE-2026-55471 | CRITICAL | 9.1 | 0.3% | Jul 8, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10... |
| CVE-2026-55470 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10... |
| CVE-2026-54777 | MEDIUM | 6.5 | 0.1% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-52200 | CRITICAL | 9.8 | 0.2% | Jul 8, 2026 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax... |
| CVE-2026-51535 | HIGH | 7.5 | 0.2% | Jul 8, 2026 | In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processi... |
| CVE-2026-48492 | MEDIUM | 6.5 | 0.4% | Jul 8, 2026 | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpo... |
| CVE-2026-44161 | HIGH | 7.2 | 0.4% | Jul 8, 2026 | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ... |
| CVE-2026-44160 | HIGH | 7.5 | 0.6% | Jul 8, 2026 | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ... |
| CVE-2026-44025 | HIGH | 7.5 | 0.5% | Jul 8, 2026 | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ... |
| CVE-2026-44024 | CRITICAL | 9.8 | 1.1% | Jul 8, 2026 | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ... |
| CVE-2026-39179 | MEDIUM | 6.3 | 0.1% | Jul 8, 2026 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t... |
| CVE-2026-39178 | MEDIUM | 6.3 | 0.1% | Jul 8, 2026 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t... |
| CVE-2026-35552 | HIGH | 8.1 | 0.2% | Jul 8, 2026 | In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remot... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now