2026 CVE Vulnerabilities
43,494 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10675 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the ... |
| CVE-2026-10674 | MEDIUM | 5.5 | 0.1% | Jul 21, 2026 | The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, cal... |
| CVE-2026-65058 | MEDIUM | 5.9 | 0.3% | Jul 21, 2026 | Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip155... |
| CVE-2026-65055 | MEDIUM | 6.9 | 0.3% | Jul 21, 2026 | Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full m... |
| CVE-2026-64822 | MEDIUM | 6.9 | 0.2% | Jul 21, 2026 | djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosi... |
| CVE-2026-64821 | MEDIUM | 5.3 | 0.1% | Jul 21, 2026 | djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated... |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A ... |
| CVE-2026-63139 | MEDIUM | 6.5 | 0.3% | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)... |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
| CVE-2026-63092 | MEDIUM | 5.3 | 0.2% | Jul 21, 2026 | kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a... |
| CVE-2026-52475 | MEDIUM | 6.1 | 0.2% | Jul 21, 2026 | Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the ... |
| CVE-2026-47714 | MEDIUM | 6.1 | 0.1% | Jul 21, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code i... |
| CVE-2026-47689 | MEDIUM | 5.2 | 0.2% | Jul 21, 2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.... |
| CVE-2026-47143 | MEDIUM | 5.9 | 0.2% | Jul 21, 2026 | Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR... |
| CVE-2026-46556 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Req... |
| CVE-2026-45383 | MEDIUM | 6.9 | 0.4% | Jul 21, 2026 | libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow... |
| CVE-2026-45382 | MEDIUM | 6.9 | 0.4% | Jul 21, 2026 | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_sl... |
| CVE-2026-16318 | MEDIUM | 6.9 | 0.4% | Jul 21, 2026 | The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store th... |
| CVE-2026-12139 | MEDIUM | 4.4 | 0.1% | Jul 21, 2026 | Tanium addressed an information disclosure vulnerability in Connect. |
| CVE-2026-65069 | MEDIUM | 4 | 0.2% | Jul 21, 2026 | Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_... |
| CVE-2026-65065 | MEDIUM | 5.5 | 0.2% | Jul 21, 2026 | Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without ... |
| CVE-2026-64613 | MEDIUM | 6.2 | 0.2% | Jul 21, 2026 | Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOL... |
| CVE-2026-59143 | MEDIUM | 6.3 | 0.2% | Jul 21, 2026 | Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offse... |
| CVE-2026-56146 | MEDIUM | 5.4 | 0.2% | Jul 21, 2026 | Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configur... |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.3% | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now