2026 CVE Vulnerabilities
57,072 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46700 | MEDIUM | 4.3 | 0.3% | Jul 7, 2026 | Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-serve... |
| CVE-2026-46672 | MEDIUM | 4.6 | 0.2% | Jul 7, 2026 | Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in pac... |
| CVE-2026-44454 | HIGH | 8.8 | 2.3% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30... |
| CVE-2026-58468 | MEDIUM | 5.5 | 0.2% | Jul 7, 2026 | NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows au... |
| CVE-2026-44877 | MEDIUM | 6.5 | 0.3% | Jul 7, 2026 | An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960... |
| CVE-2026-7017 | HIGH | 7.1 | 0.3% | Jul 7, 2026 | HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server ... |
| CVE-2026-59800 | CRITICAL | 9.8 | 1.4% | Jul 7, 2026 | 9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-i... |
| CVE-2026-59708 | HIGH | 8.7 | 0.3% | Jul 7, 2026 | The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeU... |
| CVE-2026-55435 | MEDIUM | 5.4 | 0.3% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr... |
| CVE-2026-48958 | HIGH | 8.8 | 0.3% | Jul 7, 2026 | An improper access check allows unauthorized users to create custom fields via webservices endpoints. |
| CVE-2026-48957 | HIGH | 8.8 | 0.3% | Jul 7, 2026 | An improper access check allows unauthorized users to access com_privacy datasets. |
| CVE-2026-48956 | MEDIUM | 5 | 0.3% | Jul 7, 2026 | An improper access check allows users to display a list of modules in the frontend. |
| CVE-2026-48955 | MEDIUM | 6.5 | 0.3% | Jul 7, 2026 | An improper access check allows unauthorized users to access workflow stage and transition information. |
| CVE-2026-48954 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Improper validation leads to a generic XSS vector in the language override feature. |
| CVE-2026-48953 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the generic image output layout. |
| CVE-2026-48952 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. |
| CVE-2026-48951 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. |
| CVE-2026-48950 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. |
| CVE-2026-48949 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Lack of validation leads to an XSS vulnerability in the MFA management views. |
| CVE-2026-48948 | HIGH | 8.8 | 0.3% | Jul 7, 2026 | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. |
| CVE-2026-48947 | MEDIUM | 4.9 | 0.3% | Jul 7, 2026 | An improper access check allows privileged users to overwrite media files without editing permissions. |
| CVE-2026-57851 | HIGH | 8.5 | 0.2% | Jul 7, 2026 | MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allo... |
| CVE-2026-23698 | HIGH | 8.6 | 0.9% | Jul 7, 2026 | Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import featur... |
| CVE-2026-23697 | HIGH | 8.8 | 0.8% | Jul 7, 2026 | Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve ... |
| CVE-2026-14904 | HIGH | 7.1 | 0.4% | Jul 7, 2026 | AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now