2026 CVE Vulnerabilities
57,072 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13020 | CRITICAL | 9.8 | 0.2% | Jul 7, 2026 | A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on ... |
| CVE-2026-13019 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit... |
| CVE-2026-56812 | HIGH | 7.5 | 0.4% | Jul 7, 2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript clie... |
| CVE-2026-56811 | HIGH | 7.5 | 0.4% | Jul 7, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) a... |
| CVE-2026-14969 | MEDIUM | 4.4 | 0.1% | Jul 7, 2026 | A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vecto... |
| CVE-2026-14935 | LOW | 3.7 | 0.1% | Jul 7, 2026 | A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverte... |
| CVE-2026-59709 | MEDIUM | 5.3 | 0.2% | Jul 7, 2026 | Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field wh... |
| CVE-2026-53878 | MEDIUM | 6.1 | 0.2% | Jul 7, 2026 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin... |
| CVE-2026-53877 | MEDIUM | 6.3 | 0.3% | Jul 7, 2026 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read... |
| CVE-2026-48588 | MEDIUM | 5.3 | 0.4% | Jul 7, 2026 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`... |
| CVE-2026-14940 | MEDIUM | 5.3 | 0.3% | Jul 7, 2026 | A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) ... |
| CVE-2026-12948 | MEDIUM | 4.8 | 0.3% | Jul 7, 2026 | A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP... |
| CVE-2026-12352 | MEDIUM | 5.9 | 0.3% | Jul 7, 2026 | This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on t... |
| CVE-2026-6101 | HIGH | 7.5 | — | Jul 7, 2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to a... |
| CVE-2026-53479 | HIGH | 7.2 | 1.3% | Jul 7, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-44938 | HIGH | 8.8 | — | Jul 7, 2026 | A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from na... |
| CVE-2026-53483 | CRITICAL | 9.8 | 0.6% | Jul 7, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-53481 | CRITICAL | 9.8 | 0.6% | Jul 7, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-10659 | MEDIUM | 4.7 | 0.1% | Jul 7, 2026 | The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, ... |
| CVE-2026-13696 | HIGH | 8.8 | — | Jul 7, 2026 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Lima... |
| CVE-2026-11348 | HIGH | 8.1 | — | Jul 7, 2026 | Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data... |
| CVE-2026-11340 | HIGH | 8.3 | — | Jul 7, 2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b... |
| CVE-2026-49487 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger ... |
| CVE-2026-49296 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the... |
| CVE-2026-48892 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRET... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now