2026 CVE Vulnerabilities
57,064 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3144 | CRITICAL | 9.8 | 0.4% | Jul 8, 2026 | IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized ac... |
| CVE-2026-15063 | MEDIUM | 6.3 | 0.3% | Jul 8, 2026 | A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication... |
| CVE-2026-14967 | LOW | 3.1 | 0.2% | Jul 8, 2026 | BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory... |
| CVE-2026-14966 | LOW | 3.1 | 0.3% | Jul 8, 2026 | BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it fa... |
| CVE-2026-59703 | HIGH | 8.7 | 0.4% | Jul 8, 2026 | repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to... |
| CVE-2026-55874 | HIGH | 7.7 | — | Jul 8, 2026 | SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in th... |
| CVE-2026-55873 | MEDIUM | 4.3 | — | Jul 8, 2026 | SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables ar... |
| CVE-2026-55668 | MEDIUM | 6.3 | — | Jul 8, 2026 | File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor ... |
| CVE-2026-54652 | HIGH | 8.1 | — | Jul 8, 2026 | Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any aut... |
| CVE-2026-49147 | HIGH | 7.5 | — | Jul 8, 2026 | App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output m... |
| CVE-2026-49146 | HIGH | 7.5 | — | Jul 8, 2026 | App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ac... |
| CVE-2026-49145 | HIGH | 7.5 | — | Jul 8, 2026 | App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up th... |
| CVE-2026-24700 | HIGH | 7.2 | 1.0% | Jul 8, 2026 | An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with ... |
| CVE-2026-24699 | HIGH | 7.2 | 1.0% | Jul 8, 2026 | An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with f... |
| CVE-2026-24698 | HIGH | 7.2 | 1.0% | Jul 8, 2026 | An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/... |
| CVE-2026-24697 | HIGH | 7.2 | 1.0% | Jul 8, 2026 | An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W wi... |
| CVE-2026-15067 | HIGH | 8.8 | 0.4% | Jul 8, 2026 | Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection ... |
| CVE-2026-15062 | CRITICAL | 9.6 | 0.3% | Jul 8, 2026 | SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allo... |
| CVE-2026-15044 | MEDIUM | 6.3 | 0.3% | Jul 8, 2026 | A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific s... |
| CVE-2026-15036 | MEDIUM | 4.3 | 0.4% | Jul 8, 2026 | A vulnerability was determined in Harness up to 2.28.2. This vulnerability affects the function getAuthorizedSpaces of t... |
| CVE-2026-11903 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr... |
| CVE-2026-10708 | HIGH | 7.5 | 0.1% | Jul 8, 2026 | This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a min... |
| CVE-2026-10706 | HIGH | 7.5 | 0.1% | Jul 8, 2026 | In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavi... |
| CVE-2026-10699 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). ... |
| CVE-2026-10698 | HIGH | 7.2 | 0.4% | Jul 8, 2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Report... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now