2026 CVE Vulnerabilities
43,583 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16085 | MEDIUM | 5.3 | 0.1% | Jul 18, 2026 | A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of... |
| CVE-2026-16083 | MEDIUM | 5.5 | 0.4% | Jul 18, 2026 | A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of th... |
| CVE-2026-16082 | MEDIUM | 5.3 | 0.1% | Jul 18, 2026 | A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun ... |
| CVE-2026-16081 | MEDIUM | 4.3 | 0.2% | Jul 18, 2026 | A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file w... |
| CVE-2026-16077 | MEDIUM | 5.3 | 0.2% | Jul 18, 2026 | A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file a... |
| CVE-2026-16076 | MEDIUM | 6.3 | 0.3% | Jul 18, 2026 | A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_se... |
| CVE-2026-9734 | MEDIUM | 4.3 | 0.2% | Jul 18, 2026 | The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2026-16075 | MEDIUM | 4.3 | 0.2% | Jul 18, 2026 | A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat... |
| CVE-2026-57980 | MEDIUM | 5.4 | 0.2% | Jul 17, 2026 | Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attac... |
| CVE-2026-48049 | MEDIUM | 5.3 | 0.4% | Jul 17, 2026 | @hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static file... |
| CVE-2026-48022 | MEDIUM | 6.5 | 0.1% | Jul 17, 2026 | @hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie,... |
| CVE-2026-44979 | MEDIUM | 6.3 | 0.3% | Jul 17, 2026 | @hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname,... |
| CVE-2026-54497 | MEDIUM | 6.8 | 0.2% | Jul 17, 2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4... |
| CVE-2026-54490 | MEDIUM | 6.3 | 0.4% | Jul 17, 2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the pe... |
| CVE-2026-54243 | MEDIUM | 6.1 | 0.3% | Jul 17, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission valu... |
| CVE-2026-54242 | MEDIUM | 4.9 | 0.2% | Jul 17, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image prox... |
| CVE-2026-54163 | MEDIUM | 4.7 | 0.3% | Jul 17, 2026 | secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds th... |
| CVE-2026-49977 | MEDIUM | 4.3 | 0.3% | Jul 17, 2026 | tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on... |
| CVE-2026-45785 | MEDIUM | 6.2 | 0.1% | Jul 17, 2026 | OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Sto... |
| CVE-2026-16074 | MEDIUM | 6.3 | 0.2% | Jul 17, 2026 | A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function update_plugin/update_all_plu... |
| CVE-2026-8861 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error messag... |
| CVE-2026-7771 | MEDIUM | 5.5 | 0.1% | Jul 17, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted stat... |
| CVE-2026-7754 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure defa... |
| CVE-2026-7364 | MEDIUM | 6.1 | 0.3% | Jul 17, 2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident... |
| CVE-2026-60137 | MEDIUM | 5.9 | 78.0% | Jul 17, 2026 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in p... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now