2026 CVE Vulnerabilities
43,494 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56144 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl... |
| CVE-2026-49092 | MEDIUM | 4.3 | 0.2% | Jul 21, 2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v... |
| CVE-2026-47671 | MEDIUM | 5.4 | 0.3% | Jul 21, 2026 | Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost c... |
| CVE-2026-46403 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithT... |
| CVE-2026-42397 | MEDIUM | 6.5 | 0.3% | Jul 21, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A... |
| CVE-2026-16441 | MEDIUM | 6.9 | 0.3% | Jul 21, 2026 | In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been... |
| CVE-2026-12548 | MEDIUM | 4.2 | 0.2% | Jul 21, 2026 | A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch betw... |
| CVE-2026-56577 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force o... |
| CVE-2026-47425 | MEDIUM | 6.9 | 0.1% | Jul 21, 2026 | Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `Entry... |
| CVE-2026-47411 | MEDIUM | 6.5 | — | Jul 21, 2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut... |
| CVE-2026-21577 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9... |
| CVE-2026-47408 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins... |
| CVE-2026-24232 | MEDIUM | 4.3 | — | Jul 21, 2026 | NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data... |
| CVE-2026-16454 | MEDIUM | 4.3 | 0.2% | Jul 21, 2026 | In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie... |
| CVE-2026-16451 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts... |
| CVE-2026-15342 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one wo... |
| CVE-2026-64823 | MEDIUM | 4.7 | 0.2% | Jul 21, 2026 | Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_... |
| CVE-2026-56586 | MEDIUM | 4.2 | 0.1% | Jul 21, 2026 | HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man... |
| CVE-2026-56585 | MEDIUM | 4.3 | 0.1% | Jul 21, 2026 | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the appli... |
| CVE-2026-47395 | MEDIUM | 5.5 | — | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso... |
| CVE-2026-47390 | MEDIUM | 5.5 | 0.2% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso... |
| CVE-2026-28315 | MEDIUM | 6.2 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hij... |
| CVE-2026-16450 | MEDIUM | 4.3 | 0.4% | Jul 21, 2026 | A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the ... |
| CVE-2026-16449 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted elem... |
| CVE-2026-65051 | MEDIUM | 6.9 | 0.3% | Jul 21, 2026 | Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability tha... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now