2026 CVE Vulnerabilities
43,188 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16203 | LOW | 3.5 | 0.2% | Jul 19, 2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u... |
| CVE-2026-16202 | LOW | 3.5 | 0.2% | Jul 19, 2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i... |
| CVE-2026-16156 | LOW | 3.5 | 0.2% | Jul 18, 2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown par... |
| CVE-2026-16155 | LOW | 3.5 | 0.2% | Jul 18, 2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u... |
| CVE-2026-54335 | LOW | 3.7 | 0.4% | Jul 17, 2026 | Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and ... |
| CVE-2026-54244 | LOW | 3.5 | 0.3% | Jul 17, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp... |
| CVE-2026-48978 | LOW | 2.1 | 0.3% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's ... |
| CVE-2026-50185 | LOW | 2 | 0.2% | Jul 17, 2026 | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-... |
| CVE-2026-16073 | LOW | 3.5 | 0.2% | Jul 17, 2026 | A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S... |
| CVE-2026-21764 | LOW | 3.1 | — | Jul 17, 2026 | HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric... |
| CVE-2026-21762 | LOW | 3.7 | — | Jul 17, 2026 | HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag... |
| CVE-2026-15997 | LOW | 1.7 | 0.1% | Jul 16, 2026 | Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffer... |
| CVE-2026-62994 | LOW | 3.7 | 0.3% | Jul 16, 2026 | CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreD... |
| CVE-2026-47088 | LOW | 3.1 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi... |
| CVE-2026-47087 | LOW | 3.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A... |
| CVE-2026-47086 | LOW | 3.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe... |
| CVE-2026-47081 | LOW | 3.1 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac... |
| CVE-2026-44969 | LOW | 3.3 | 0.1% | Jul 16, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/... |
| CVE-2026-15945 | LOW | 2.7 | 0.2% | Jul 16, 2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin ... |
| CVE-2026-35145 | LOW | 3.1 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to ... |
| CVE-2026-12907 | LOW | 2.7 | 0.1% | Jul 16, 2026 | The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions,... |
| CVE-2026-12906 | LOW | 2.7 | 0.1% | Jul 16, 2026 | The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a r... |
| CVE-2026-38755 | LOW | 2.9 | 0.3% | Jul 15, 2026 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Ser... |
| CVE-2026-38752 | LOW | 2.9 | 0.3% | Jul 15, 2026 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial ... |
| CVE-2026-15921 | LOW | 3.1 | 0.2% | Jul 15, 2026 | Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now