2026 CVE Vulnerabilities
43,564 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64192 | MEDIUM | 5.5 | 0.2% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if ... |
| CVE-2026-64190 | MEDIUM | 5.5 | 0.1% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: team: fix NULL pointer dereference in team_xmi... |
| CVE-2026-64187 | MEDIUM | 5.5 | 0.2% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no ... |
| CVE-2026-58482 | MEDIUM | 5.9 | 0.1% | Jul 20, 2026 | Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalI... |
| CVE-2026-58481 | MEDIUM | 6.5 | 0.1% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped fil... |
| CVE-2026-58414 | MEDIUM | 5.5 | 0.1% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recu... |
| CVE-2026-58413 | MEDIUM | 6.1 | 0.1% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, b... |
| CVE-2026-55645 | MEDIUM | 6.5 | 0.5% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client... |
| CVE-2026-55238 | MEDIUM | 5.3 | 0.5% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Co... |
| CVE-2026-50743 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or ... |
| CVE-2026-47276 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attac... |
| CVE-2026-44978 | MEDIUM | 5.3 | 0.5% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the ... |
| CVE-2026-42218 | MEDIUM | 5.3 | 0.4% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login in... |
| CVE-2026-42210 | MEDIUM | 5.3 | 0.4% | Jul 20, 2026 | Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that... |
| CVE-2026-35590 | MEDIUM | 6.8 | 0.1% | Jul 20, 2026 | libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and in... |
| CVE-2026-35217 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the fi... |
| CVE-2026-33328 | MEDIUM | 6.8 | 0.1% | Jul 20, 2026 | libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.1... |
| CVE-2026-32823 | MEDIUM | 4.3 | 0.1% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-32819 | MEDIUM | 4.3 | 0.2% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-6793 | MEDIUM | 5.4 | — | Jul 20, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering ... |
| CVE-2026-63428 | MEDIUM | 5.8 | 0.2% | Jul 20, 2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id,... |
| CVE-2026-63102 | MEDIUM | 5.4 | 0.2% | Jul 20, 2026 | rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitr... |
| CVE-2026-51026 | MEDIUM | 6.5 | 0.8% | Jul 20, 2026 | Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a ... |
| CVE-2026-48824 | MEDIUM | 5.3 | 0.3% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2... |
| CVE-2026-46671 | MEDIUM | 4.4 | 0.1% | Jul 20, 2026 | Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciou... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now