2026 CVE Vulnerabilities
57,068 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56283 | MEDIUM | 5.4 | — | Jul 8, 2026 | Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attacke... |
| CVE-2026-56273 | MEDIUM | 6.5 | 0.3% | Jul 8, 2026 | Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that ... |
| CVE-2026-56250 | HIGH | 8.7 | — | Jul 8, 2026 | Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, ... |
| CVE-2026-56246 | HIGH | 8.1 | — | Jul 8, 2026 | Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A... |
| CVE-2026-56226 | HIGH | 8.7 | — | Jul 8, 2026 | Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which ... |
| CVE-2026-56220 | HIGH | 7.1 | — | Jul 8, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows re... |
| CVE-2026-56217 | MEDIUM | 5.3 | — | Jul 8, 2026 | Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped A... |
| CVE-2026-56086 | HIGH | 8.8 | — | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-54061 | CRITICAL | 9.1 | — | Jul 8, 2026 | Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for e... |
| CVE-2026-53482 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-53480 | LOW | 2.7 | — | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-44840 | HIGH | 7.5 | 0.5% | Jul 8, 2026 | Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in... |
| CVE-2026-41122 | HIGH | 7.1 | — | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-22927 | HIGH | 7.8 | 0.2% | Jul 8, 2026 | Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability. |
| CVE-2026-15053 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Tanium addressed a denial of service vulnerability in Tanium Server. |
| CVE-2026-15035 | HIGH | 7.8 | 0.6% | Jul 8, 2026 | A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm... |
| CVE-2026-15034 | MEDIUM | 4.3 | — | Jul 8, 2026 | A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some ... |
| CVE-2026-15033 | MEDIUM | 6.3 | — | Jul 8, 2026 | A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the f... |
| CVE-2026-8315 | MEDIUM | 5.4 | — | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig... |
| CVE-2026-8310 | MEDIUM | 6.1 | — | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig... |
| CVE-2026-8307 | CRITICAL | 9.8 | — | Jul 8, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Desig... |
| CVE-2026-6820 | HIGH | 7.2 | — | Jul 8, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema... |
| CVE-2026-6740 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2026-6459 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-5459 | MEDIUM | 5.3 | — | Jul 8, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now