2026 CVE Vulnerabilities
59,863 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14160 | MEDIUM | 5.9 | 0.1% | Jun 30, 2026 | Time-of-check time-of-use (TOCTOU) race condition vulnerability in Samsung Open Source Escargot allows Leveraging Race C... |
| CVE-2026-12114 | MEDIUM | 4.4 | 0.2% | Jun 30, 2026 | The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2026-58302 | HIGH | 8.4 | 0.2% | Jun 30, 2026 | rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads s... |
| CVE-2026-12243 | — | — | 0.6% | Jun 30, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-8023 | HIGH | 7.5 | 0.9% | Jun 29, 2026 | Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, ava... |
| CVE-2026-7656 | MEDIUM | 6.8 | 0.3% | Jun 29, 2026 | The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) use... |
| CVE-2026-51219 | HIGH | 7.5 | 0.3% | Jun 29, 2026 | A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows... |
| CVE-2026-51218 | HIGH | 7.5 | 0.3% | Jun 29, 2026 | A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows at... |
| CVE-2026-10648 | MEDIUM | 5.5 | 0.1% | Jun 29, 2026 | mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of sm... |
| CVE-2026-57997 | MEDIUM | 5.4 | 0.1% | Jun 29, 2026 | Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not exp... |
| CVE-2026-51221 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a D... |
| CVE-2026-34592 | HIGH | 7.7 | 0.2% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-10647 | MEDIUM | 5.3 | 0.2% | Jun 29, 2026 | The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue()... |
| CVE-2026-55957 | HIGH | 7.3 | 0.3% | Jun 29, 2026 | Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate... |
| CVE-2026-55956 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ig... |
| CVE-2026-55955 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the ... |
| CVE-2026-55276 | CRITICAL | 9.1 | 0.3% | Jun 29, 2026 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisa... |
| CVE-2026-53434 | CRITICAL | 9.1 | 0.3% | Jun 29, 2026 | Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connect... |
| CVE-2026-53404 | HIGH | 7.3 | 0.2% | Jun 29, 2026 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first cond... |
| CVE-2026-50229 | MEDIUM | 6.1 | 0.2% | Jun 29, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example ... |
| CVE-2026-41896 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34597 | HIGH | 8.8 | 0.5% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34594 | HIGH | 8.8 | 1.1% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-13758 | LOW | 3.7 | 0.2% | Jun 29, 2026 | CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt... |
| CVE-2026-57919 | HIGH | 7.8 | 0.1% | Jun 29, 2026 | PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now