2026 CVE Vulnerabilities
57,147 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54260 | LOW | 2.7 | 0.2% | Jul 1, 2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an aut... |
| CVE-2026-54259 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Do... |
| CVE-2026-52190 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-52186 | CRITICAL | 9.8 | 0.3% | Jul 1, 2026 | SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary cod... |
| CVE-2026-38891 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cau... |
| CVE-2026-36912 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3... |
| CVE-2026-36911 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE befor... |
| CVE-2026-36910 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers... |
| CVE-2026-36909 | MEDIUM | 6.2 | 0.2% | Jul 1, 2026 | A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allow... |
| CVE-2026-58263 | HIGH | 7.2 | 0.2% | Jul 1, 2026 | Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in... |
| CVE-2026-55886 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to ... |
| CVE-2026-55661 | MEDIUM | 4.8 | 0.2% | Jul 1, 2026 | Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and tinacms 3.9.3, rich-text par... |
| CVE-2026-55660 | HIGH | 7.6 | 0.2% | Jul 1, 2026 | Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin po... |
| CVE-2026-55153 | HIGH | 7.1 | 0.3% | Jul 1, 2026 | mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool.... |
| CVE-2026-54786 | MEDIUM | 5 | 0.2% | Jul 1, 2026 | Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; ver... |
| CVE-2026-54756 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior ... |
| CVE-2026-54720 | MEDIUM | 5.4 | 0.3% | Jul 1, 2026 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert med... |
| CVE-2026-54074 | HIGH | 7.8 | 0.2% | Jul 1, 2026 | Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulne... |
| CVE-2026-50521 | HIGH | 8.3 | 0.8% | Jul 1, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. |
| CVE-2026-14340 | MEDIUM | 5 | 0.3% | Jul 1, 2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token ... |
| CVE-2026-58593 | HIGH | 8.7 | 0.2% | Jul 1, 2026 | NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound ... |
| CVE-2026-58592 | HIGH | 8.3 | 0.5% | Jul 1, 2026 | Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration modul... |
| CVE-2026-58457 | CRITICAL | 9.8 | 1.7% | Jul 1, 2026 | Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability... |
| CVE-2026-55688 | MEDIUM | 4 | 0.2% | Jul 1, 2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2026-54908 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now