2026 CVE Vulnerabilities
57,111 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46463 | MEDIUM | 6.5 | 0.2% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-59234 | MEDIUM | 6.9 | 0.4% | Jul 3, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calend... |
| CVE-2026-56085 | LOW | 3.3 | 0.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-56015 | CRITICAL | 9.1 | 0.6% | Jul 3, 2026 | Net::IP::LPM versions before 1.11 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes... |
| CVE-2026-54483 | MEDIUM | 6.7 | 0.5% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-46730 | MEDIUM | 4.2 | 0.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-46468 | MEDIUM | 4.4 | 0.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-46467 | MEDIUM | 5.8 | 0.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-44269 | MEDIUM | 4.4 | 0.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-44268 | MEDIUM | 4.4 | 0.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-41124 | MEDIUM | 4.4 | 0.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-41123 | MEDIUM | 4.3 | 0.2% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-26355 | MEDIUM | 6.5 | 1.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-50238 | — | — | — | Jul 3, 2026 | Rejected reason: Red Hat Product Security has concluded that this CVE is not required. The reported issue has been class... |
| CVE-2026-13341 | HIGH | 7.4 | 0.3% | Jul 3, 2026 | A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow... |
| CVE-2026-10055 | HIGH | 8.5 | 0.3% | Jul 3, 2026 | In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from... |
| CVE-2026-10054 | HIGH | 8.8 | 0.2% | Jul 3, 2026 | In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc... |
| CVE-2026-5137 | MEDIUM | 4.3 | 0.3% | Jul 3, 2026 | The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and i... |
| CVE-2026-4322 | MEDIUM | 6.1 | 0.1% | Jul 3, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web... |
| CVE-2026-4321 | CRITICAL | 9.8 | 0.3% | Jul 3, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web... |
| CVE-2026-9756 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldTy... |
| CVE-2026-4804 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, a... |
| CVE-2026-47896 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen... |
| CVE-2026-35159 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attack... |
| CVE-2026-11900 | MEDIUM | 4.3 | 0.3% | Jul 3, 2026 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in ver... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now