2026 CVE Vulnerabilities
57,147 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54164 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and... |
| CVE-2026-49858 | MEDIUM | 5.9 | 0.2% | Jul 1, 2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29,... |
| CVE-2026-14363 | CRITICAL | 9.8 | 0.3% | Jul 1, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun... |
| CVE-2026-14265 | HIGH | 8.8 | 0.4% | Jul 1, 2026 | Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 t... |
| CVE-2026-58517 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension ... |
| CVE-2026-58451 | HIGH | 7.1 | 0.4% | Jul 1, 2026 | Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to... |
| CVE-2026-55628 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.... |
| CVE-2026-55597 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26... |
| CVE-2026-55595 | MEDIUM | 4.7 | 0.1% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-55594 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-55577 | MEDIUM | 5.9 | 0.2% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-55510 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-53492 | CRITICAL | 9.6 | 0.5% | Jul 1, 2026 | containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation impr... |
| CVE-2026-53489 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plu... |
| CVE-2026-53467 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-53466 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-51947 | CRITICAL | 9.8 | 0.6% | Jul 1, 2026 | An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 a... |
| CVE-2026-50195 | CRITICAL | 9.9 | 0.3% | Jul 1, 2026 | containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the ... |
| CVE-2026-50160 | CRITICAL | 10 | 0.6% | Jul 1, 2026 | Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and e... |
| CVE-2026-49119 | HIGH | 8.7 | 0.7% | Jul 1, 2026 | Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that all... |
| CVE-2026-47262 | MEDIUM | 5.5 | 0.5% | Jul 1, 2026 | containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vuln... |
| CVE-2026-41121 | HIGH | 7.8 | 0.1% | Jul 1, 2026 | Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Lin... |
| CVE-2026-38142 | MEDIUM | 6.5 | 0.7% | Jul 1, 2026 | An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.0... |
| CVE-2026-14358 | MEDIUM | 6.1 | 0.3% | Jul 1, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-13769 | MEDIUM | 6.8 | — | Jul 1, 2026 | Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now