2026 CVE Vulnerabilities
57,072 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-37270 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper passwor... |
| CVE-2026-36163 | MEDIUM | 5.4 | 0.2% | Jul 7, 2026 | An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execut... |
| CVE-2026-36162 | MEDIUM | 5.4 | 0.1% | Jul 7, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 all... |
| CVE-2026-14895 | HIGH | 7.5 | 0.2% | Jul 7, 2026 | String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtri... |
| CVE-2026-14740 | CRITICAL | 9.1 | 0.4% | Jul 7, 2026 | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The pr... |
| CVE-2026-14739 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeho... |
| CVE-2026-14380 | HIGH | 8.8 | 0.5% | Jul 7, 2026 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is ass... |
| CVE-2026-59706 | CRITICAL | 9.3 | 0.3% | Jul 7, 2026 | mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f... |
| CVE-2026-59153 | LOW | 2.1 | 0.2% | Jul 7, 2026 | Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve me... |
| CVE-2026-58266 | MEDIUM | 6.5 | 0.2% | Jul 7, 2026 | Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with t... |
| CVE-2026-55490 | MEDIUM | 6.5 | 0.6% | Jul 7, 2026 | OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a()... |
| CVE-2026-55418 | HIGH | 8.6 | 0.3% | Jul 7, 2026 | FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unr... |
| CVE-2026-55408 | HIGH | 8.4 | 0.2% | Jul 7, 2026 | Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution throu... |
| CVE-2026-55075 | HIGH | 7.4 | 0.5% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-54698 | MEDIUM | 5.9 | 0.2% | Jul 7, 2026 | Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a ... |
| CVE-2026-54607 | HIGH | 7.7 | 0.2% | Jul 7, 2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer valid... |
| CVE-2026-54602 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates t... |
| CVE-2026-54601 | MEDIUM | 6.3 | 0.2% | Jul 7, 2026 | FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticat... |
| CVE-2026-50179 | MEDIUM | 4.2 | 0.3% | Jul 7, 2026 | Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/s... |
| CVE-2026-49229 | HIGH | 8.3 | 0.4% | Jul 7, 2026 | Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks f... |
| CVE-2026-49033 | HIGH | 8.4 | 0.1% | Jul 7, 2026 | The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arb... |
| CVE-2026-46354 | CRITICAL | 9.1 | 0.3% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29... |
| CVE-2026-45796 | MEDIUM | 6.5 | 0.3% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13... |
| CVE-2026-42958 | HIGH | 8.4 | 0.1% | Jul 7, 2026 | The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing s... |
| CVE-2026-42953 | HIGH | 8.4 | 0.1% | Jul 7, 2026 | The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now