2026 CVE Vulnerabilities
59,898 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55955 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the ... |
| CVE-2026-55276 | CRITICAL | 9.1 | 0.3% | Jun 29, 2026 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisa... |
| CVE-2026-53434 | CRITICAL | 9.1 | 0.3% | Jun 29, 2026 | Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connect... |
| CVE-2026-53404 | HIGH | 7.3 | 0.2% | Jun 29, 2026 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first cond... |
| CVE-2026-50229 | MEDIUM | 6.1 | 0.2% | Jun 29, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example ... |
| CVE-2026-41896 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34597 | HIGH | 8.8 | 0.5% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34594 | HIGH | 8.8 | 1.1% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-13758 | LOW | 3.7 | 0.2% | Jun 29, 2026 | CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt... |
| CVE-2026-57919 | HIGH | 7.8 | 0.1% | Jun 29, 2026 | PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA... |
| CVE-2026-57498 | CRITICAL | 9.6 | 0.2% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-56018 | HIGH | 7.5 | 0.6% | Jun 29, 2026 | JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory ... |
| CVE-2026-56017 | HIGH | 7.5 | 0.5% | Jun 29, 2026 | JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful t... |
| CVE-2026-54889 | MEDIUM | 5.1 | 0.3% | Jun 29, 2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scri... |
| CVE-2026-54888 | MEDIUM | 6.9 | 0.2% | Jun 29, 2026 | Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex ... |
| CVE-2026-53429 | MEDIUM | 6.9 | 0.1% | Jun 29, 2026 | Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker wh... |
| CVE-2026-53426 | HIGH | 8.2 | 0.1% | Jun 29, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.... |
| CVE-2026-43746 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 ... |
| CVE-2026-43745 | MEDIUM | 6.5 | 0.7% | Jun 29, 2026 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.... |
| CVE-2026-43743 | MEDIUM | 4.7 | 0.1% | Jun 29, 2026 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, iOS 26... |
| CVE-2026-43742 | MEDIUM | 6.5 | 0.4% | Jun 29, 2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 ... |
| CVE-2026-43740 | MEDIUM | 6.5 | 0.4% | Jun 29, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.... |
| CVE-2026-43735 | HIGH | 8.1 | 0.3% | Jun 29, 2026 | The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS ... |
| CVE-2026-43734 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 ... |
| CVE-2026-43732 | MEDIUM | 6.5 | 0.4% | Jun 29, 2026 | A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadO... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now