2026 CVE Vulnerabilities
57,060 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31309 | CRITICAL | 9.8 | 0.3% | Jul 8, 2026 | Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows a... |
| CVE-2026-15168 | LOW | 3.3 | 0.1% | Jul 8, 2026 | BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure |
| CVE-2026-10037 | HIGH | 8.8 | 0.1% | Jul 8, 2026 | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by th... |
| CVE-2026-8472 | MEDIUM | 4.3 | 0.2% | Jul 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.... |
| CVE-2026-7492 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 1... |
| CVE-2026-6896 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19... |
| CVE-2026-6352 | LOW | 2.7 | 0.3% | Jul 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.... |
| CVE-2026-60105 | HIGH | 8.6 | 0.3% | Jul 8, 2026 | Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an... |
| CVE-2026-59818 | HIGH | 8.1 | 0.4% | Jul 8, 2026 | etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is con... |
| CVE-2026-58525 | HIGH | 8.2 | 0.4% | Jul 8, 2026 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature ... |
| CVE-2026-58494 | MEDIUM | 6.5 | 0.1% | Jul 8, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation a... |
| CVE-2026-58211 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58208 | HIGH | 7.5 | 0.5% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58207 | MEDIUM | 6.5 | 0.5% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58192 | CRITICAL | 10 | 0.5% | Jul 8, 2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior... |
| CVE-2026-58191 | MEDIUM | 6.1 | 0.3% | Jul 8, 2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior... |
| CVE-2026-57481 | LOW | 2.3 | 0.4% | Jul 8, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a... |
| CVE-2026-57480 | HIGH | 8.7 | 0.3% | Jul 8, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a... |
| CVE-2026-56669 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun... |
| CVE-2026-55778 | LOW | 2.1 | 0.4% | Jul 8, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a... |
| CVE-2026-55596 | HIGH | 8.7 | 0.2% | Jul 8, 2026 | Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized ... |
| CVE-2026-55542 | MEDIUM | 4.3 | 0.4% | Jul 8, 2026 | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks a... |
| CVE-2026-55206 | HIGH | 8.7 | 0.3% | Jul 8, 2026 | py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio... |
| CVE-2026-55195 | HIGH | 8.7 | 0.3% | Jul 8, 2026 | py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio... |
| CVE-2026-54591 | HIGH | 8.1 | 0.3% | Jul 8, 2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now