2026 CVE Vulnerabilities
59,305 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53332 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after cr... |
| CVE-2026-53331 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl-... |
| CVE-2026-53330 | HIGH | 7.1 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds read in dp_get_e... |
| CVE-2026-53329 | HIGH | 7 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector... |
| CVE-2026-53328 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't warn on NULL cgrp_moving_from in s... |
| CVE-2026-53327 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: debugobjects: Do not fill_pool() if pi_blocked_on ... |
| CVE-2026-53326 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_pool() in early boot ... |
| CVE-2026-13603 | CRITICAL | 9 | 0.3% | Jul 1, 2026 | The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially othe... |
| CVE-2026-8387 | LOW | 2.4 | 0.4% | Jul 1, 2026 | A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path traversal when extract... |
| CVE-2026-5120 | HIGH | 8.1 | 0.2% | Jul 1, 2026 | A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to ac... |
| CVE-2026-53909 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side... |
| CVE-2026-53908 | MEDIUM | 4.3 | 0.3% | Jul 1, 2026 | MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguis... |
| CVE-2026-53907 | MEDIUM | 5.4 | 0.3% | Jul 1, 2026 | MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with t... |
| CVE-2026-53906 | HIGH | 8.2 | 0.4% | Jul 1, 2026 | MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload... |
| CVE-2026-53905 | HIGH | 7.1 | 0.2% | Jul 1, 2026 | MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree... |
| CVE-2026-53904 | HIGH | 7.1 | 0.2% | Jul 1, 2026 | MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each pass... |
| CVE-2026-53903 | HIGH | 8.1 | 0.2% | Jul 1, 2026 | MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/tradin... |
| CVE-2026-53902 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership... |
| CVE-2026-14198 | CRITICAL | 9.1 | 0.3% | Jul 1, 2026 | @fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching m... |
| CVE-2026-14181 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when... |
| CVE-2026-13323 | HIGH | 8.7 | 0.2% | Jul 1, 2026 | In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/h... |
| CVE-2026-14258 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Ad... |
| CVE-2026-13228 | HIGH | 8.8 | — | Jul 1, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca... |
| CVE-2026-12142 | HIGH | 7.2 | — | Jul 1, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2026-10095 | MEDIUM | 6.4 | — | Jul 1, 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now