2026 CVE Vulnerabilities
58,076 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59100 | MEDIUM | 5 | 0.2% | Jul 2, 2026 | LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to... |
| CVE-2026-59099 | CRITICAL | 9.3 | 0.4% | Jul 2, 2026 | Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to... |
| CVE-2026-59098 | HIGH | 7.1 | 0.2% | Jul 2, 2026 | LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic sea... |
| CVE-2026-59097 | MEDIUM | 6.9 | 0.3% | Jul 2, 2026 | Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to creat... |
| CVE-2026-59096 | HIGH | 8.2 | 0.2% | Jul 2, 2026 | Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document ... |
| CVE-2026-59095 | HIGH | 8.3 | 0.2% | Jul 2, 2026 | LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attacker... |
| CVE-2026-59094 | HIGH | 8.7 | 0.5% | Jul 2, 2026 | Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed docume... |
| CVE-2026-59093 | HIGH | 8.8 | 0.4% | Jul 2, 2026 | Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted... |
| CVE-2026-59092 | CRITICAL | 9.8 | 0.3% | Jul 2, 2026 | JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthentica... |
| CVE-2026-58580 | MEDIUM | 6 | 0.2% | Jul 2, 2026 | LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. ... |
| CVE-2026-58579 | MEDIUM | 5.4 | 0.2% | Jul 2, 2026 | RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalize... |
| CVE-2026-58578 | HIGH | 7.1 | 0.3% | Jul 2, 2026 | LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allo... |
| CVE-2026-58467 | HIGH | 8.2 | 0.4% | Jul 2, 2026 | Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated ... |
| CVE-2026-58466 | CRITICAL | 9.8 | 0.5% | Jul 2, 2026 | AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers t... |
| CVE-2026-58381 | MEDIUM | 6.1 | 0.1% | Jul 2, 2026 | A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe... |
| CVE-2026-52187 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-7311 | HIGH | 8.1 | 0.7% | Jul 2, 2026 | The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to in... |
| CVE-2026-58465 | HIGH | 8.7 | 0.6% | Jul 2, 2026 | Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 hand... |
| CVE-2026-13743 | LOW | 3.3 | 0.1% | Jul 2, 2026 | CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptogr... |
| CVE-2026-8699 | HIGH | 7 | — | Jul 2, 2026 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5... |
| CVE-2026-55952 | HIGH | 7.5 | 0.5% | Jul 2, 2026 | The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientH... |
| CVE-2026-55950 | MEDIUM | 5.9 | 0.4% | Jul 2, 2026 | Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an u... |
| CVE-2026-54891 | LOW | 3.7 | 0.1% | Jul 2, 2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl... |
| CVE-2026-54887 | MEDIUM | 4.8 | 0.2% | Jul 2, 2026 | Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computatio... |
| CVE-2026-54886 | MEDIUM | 4.3 | 0.3% | Jul 2, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an auth... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now