2026 CVE Vulnerabilities
57,083 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58402 | MEDIUM | 5.4 | 0.3% | Jul 6, 2026 | Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-f... |
| CVE-2026-55646 | MEDIUM | 6.5 | 0.3% | Jul 6, 2026 | vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions a... |
| CVE-2026-53763 | LOW | 3.8 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-50134 | MEDIUM | 5.8 | 0.3% | Jul 6, 2026 | Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL i... |
| CVE-2026-50133 | MEDIUM | 6.1 | 0.3% | Jul 6, 2026 | Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to... |
| CVE-2026-44362 | MEDIUM | 5.5 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-42546 | LOW | 3.8 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-41516 | LOW | 3.3 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-41515 | LOW | 3.3 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-41514 | LOW | 3.3 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-14898 | MEDIUM | 6.5 | 0.2% | Jul 6, 2026 | The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could pl... |
| CVE-2026-14536 | HIGH | 8.8 | 0.3% | Jul 6, 2026 | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack... |
| CVE-2026-11405 | CRITICAL | 9.8 | 0.2% | Jul 6, 2026 | The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8... |
| CVE-2026-9182 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is... |
| CVE-2026-9181 | HIGH | 7.5 | 0.7% | Jul 6, 2026 | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una... |
| CVE-2026-55798 | MEDIUM | 4.5 | 0.1% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by ... |
| CVE-2026-55380 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from t... |
| CVE-2026-55379 | HIGH | 7.5 | 0.4% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field f... |
| CVE-2026-54291 | MEDIUM | 5.9 | 0.3% | Jul 6, 2026 | pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections ... |
| CVE-2026-54060 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into ... |
| CVE-2026-54059 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the P... |
| CVE-2026-13753 | HIGH | 7.5 | 0.5% | Jul 6, 2026 | Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenti... |
| CVE-2026-48614 | CRITICAL | 9.9 | — | Jul 6, 2026 | An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configurat... |
| CVE-2026-41434 | LOW | 3.3 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-12154 | MEDIUM | 6.4 | 0.2% | Jul 6, 2026 | The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now