2026 CVE Vulnerabilities
57,147 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13760 | HIGH | 7.3 | — | Jul 1, 2026 | OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platfor... |
| CVE-2026-5051 | MEDIUM | 4.4 | 0.3% | Jul 1, 2026 | HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin dire... |
| CVE-2026-58521 | CRITICAL | 9.8 | 0.3% | Jul 1, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun... |
| CVE-2026-58520 | MEDIUM | 6.1 | 0.3% | Jul 1, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener E... |
| CVE-2026-57737 | MEDIUM | 6.5 | — | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortco... |
| CVE-2026-57736 | HIGH | 7.4 | — | Jul 1, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. Thi... |
| CVE-2026-57723 | HIGH | 7.4 | — | Jul 1, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal.... |
| CVE-2026-57722 | MEDIUM | 5.9 | 0.1% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable ... |
| CVE-2026-54428 | HIGH | 7.5 | 0.6% | Jul 1, 2026 | Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 an... |
| CVE-2026-51946 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary... |
| CVE-2026-49091 | HIGH | 8 | 0.2% | Jul 1, 2026 | Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forgin... |
| CVE-2026-49090 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (C... |
| CVE-2026-46680 | HIGH | 7.8 | 0.2% | Jul 1, 2026 | containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched... |
| CVE-2026-58454 | HIGH | 7.7 | 0.5% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that ... |
| CVE-2026-58453 | CRITICAL | 9.8 | 1.7% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that... |
| CVE-2026-58452 | HIGH | 8.8 | 2.4% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that ... |
| CVE-2026-57721 | MEDIUM | 5.3 | — | Jul 1, 2026 | Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-57720 | MEDIUM | 4.3 | — | Jul 1, 2026 | Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-57516 | HIGH | 8.8 | 0.5% | Jul 1, 2026 | Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a... |
| CVE-2026-56152 | MEDIUM | 5.3 | 0.3% | Jul 1, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality ... |
| CVE-2026-56151 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An... |
| CVE-2026-56150 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Exces... |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.3% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce... |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). ... |
| CVE-2026-54399 | HIGH | 7.5 | 0.6% | Jul 1, 2026 | Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now