2026 CVE Vulnerabilities
57,076 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11340 | HIGH | 8.3 | — | Jul 7, 2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b... |
| CVE-2026-49487 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger ... |
| CVE-2026-49296 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the... |
| CVE-2026-48892 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRET... |
| CVE-2026-48891 | MEDIUM | 4.3 | 0.4% | Jul 7, 2026 | A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the t... |
| CVE-2026-48828 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `shoul... |
| CVE-2026-33264 | CRITICAL | 9.8 | 1.1% | Jul 7, 2026 | A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths whe... |
| CVE-2026-14868 | MEDIUM | 5.5 | 0.1% | Jul 7, 2026 | The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of Pc... |
| CVE-2026-14867 | MEDIUM | 5.5 | 0.1% | Jul 7, 2026 | Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.... |
| CVE-2026-14476 | HIGH | 8 | 0.7% | Jul 7, 2026 | A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitiz... |
| CVE-2026-14474 | HIGH | 8.8 | 0.6% | Jul 7, 2026 | A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD ... |
| CVE-2026-11610 | HIGH | 8.8 | 0.6% | Jul 7, 2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SA... |
| CVE-2026-58384 | HIGH | 7.8 | 0.2% | Jul 7, 2026 | A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation... |
| CVE-2026-13199 | MEDIUM | 5.1 | 0.1% | Jul 7, 2026 | EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resul... |
| CVE-2026-8377 | HIGH | 8.2 | 0.2% | Jul 7, 2026 | Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Colle... |
| CVE-2026-8309 | MEDIUM | 5.4 | 0.1% | Jul 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information... |
| CVE-2026-8306 | MEDIUM | 6.1 | 0.1% | Jul 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information... |
| CVE-2026-7380 | MEDIUM | 6.1 | 0.1% | Jul 7, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno... |
| CVE-2026-5799 | HIGH | 7.5 | 0.2% | Jul 7, 2026 | Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a... |
| CVE-2026-5730 | HIGH | 7.5 | 0.2% | Jul 7, 2026 | Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a... |
| CVE-2026-58315 | MEDIUM | 5.1 | 0.1% | Jul 7, 2026 | Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged... |
| CVE-2026-57871 | HIGH | 7.1 | 0.4% | Jul 7, 2026 | Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overw... |
| CVE-2026-57870 | MEDIUM | 5.3 | 0.2% | Jul 7, 2026 | Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document template... |
| CVE-2026-57869 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat... |
| CVE-2026-57868 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects M... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now