2026 CVE Vulnerabilities
59,953 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13495 | MEDIUM | 4.7 | 0.2% | Jun 28, 2026 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the fi... |
| CVE-2026-13493 | LOW | 3.1 | 0.2% | Jun 28, 2026 | A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file ba... |
| CVE-2026-13491 | LOW | 3.7 | 0.4% | Jun 28, 2026 | A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetIn... |
| CVE-2026-13490 | MEDIUM | 6.3 | 0.3% | Jun 28, 2026 | A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document... |
| CVE-2026-13489 | LOW | 3.1 | 0.2% | Jun 28, 2026 | A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of t... |
| CVE-2026-13488 | HIGH | 7.3 | 0.3% | Jun 28, 2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vuln... |
| CVE-2026-13487 | HIGH | 7.3 | 0.3% | Jun 28, 2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function ... |
| CVE-2026-13486 | HIGH | 7.3 | 0.4% | Jun 28, 2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown fu... |
| CVE-2026-13485 | HIGH | 7.3 | 0.4% | Jun 28, 2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of t... |
| CVE-2026-13484 | HIGH | 8.8 | 0.2% | Jun 28, 2026 | A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unkn... |
| CVE-2026-13483 | LOW | 3.1 | 0.1% | Jun 28, 2026 | A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the fil... |
| CVE-2026-13482 | LOW | 3.7 | 0.2% | Jun 28, 2026 | A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file... |
| CVE-2026-10646 | HIGH | 7.4 | 0.3% | Jun 28, 2026 | Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-all... |
| CVE-2026-10644 | LOW | 3.1 | 0.1% | Jun 28, 2026 | The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains ... |
| CVE-2026-10593 | MEDIUM | 6.5 | 0.2% | Jun 28, 2026 | The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications.... |
| CVE-2026-58058 | MEDIUM | 6.9 | 0.3% | Jun 28, 2026 | Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (li... |
| CVE-2026-58057 | MEDIUM | 5 | 0.2% | Jun 28, 2026 | Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparis... |
| CVE-2026-58056 | HIGH | 7.6 | 0.2% | Jun 28, 2026 | RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type... |
| CVE-2026-58055 | MEDIUM | 6.3 | 0.2% | Jun 28, 2026 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header an... |
| CVE-2026-58054 | — | — | 0.3% | Jun 28, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE was assigned on the... |
| CVE-2026-58053 | CRITICAL | 9.9 | 0.3% | Jun 28, 2026 | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docke... |
| CVE-2026-58052 | MEDIUM | 4.8 | 0.1% | Jun 28, 2026 | 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because it... |
| CVE-2026-58051 | HIGH | 8.3 | 0.3% | Jun 28, 2026 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsin... |
| CVE-2026-58050 | HIGH | 7.5 | 0.3% | Jun 28, 2026 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses ... |
| CVE-2026-58049 | HIGH | 8.6 | 0.3% | Jun 28, 2026 | FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now