2026 CVE Vulnerabilities
57,072 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59998 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th... |
| CVE-2026-59997 | MEDIUM | 5.4 | 0.2% | Jul 8, 2026 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important ... |
| CVE-2026-59996 | MEDIUM | 5.4 | 0.2% | Jul 8, 2026 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee... |
| CVE-2026-59995 | MEDIUM | 5.4 | 0.2% | Jul 8, 2026 | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u... |
| CVE-2026-56843 | CRITICAL | 9.9 | 0.3% | Jul 8, 2026 | Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated custo... |
| CVE-2026-55438 | MEDIUM | 6.8 | 0.2% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7... |
| CVE-2026-55437 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7... |
| CVE-2026-55436 | HIGH | 7.4 | 0.3% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr... |
| CVE-2026-55433 | MEDIUM | 5.4 | 0.4% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55432 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55431 | MEDIUM | 6.1 | 0.4% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55430 | MEDIUM | 6.8 | 0.2% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55429 | HIGH | 8.7 | 0.5% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55428 | HIGH | 8.2 | 0.4% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55427 | HIGH | 8.3 | 0.5% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55079 | MEDIUM | 6.5 | 0.6% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and pr... |
| CVE-2026-59705 | CRITICAL | 9.8 | 0.5% | Jul 7, 2026 | mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers t... |
| CVE-2026-59704 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metada... |
| CVE-2026-55078 | MEDIUM | 6.5 | 0.6% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and pr... |
| CVE-2026-55077 | HIGH | 7.2 | 0.6% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55076 | HIGH | 7.4 | 0.5% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-51937 | HIGH | 7.5 | 0.4% | Jul 7, 2026 | An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsAp... |
| CVE-2026-50811 | MEDIUM | 6.5 | 0.3% | Jul 7, 2026 | An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736... |
| CVE-2026-50810 | MEDIUM | 5.5 | 0.1% | Jul 7, 2026 | A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35... |
| CVE-2026-37271 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GA... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now