2026 CVE Vulnerabilities
43,635 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48008 | MEDIUM | 6.5 | — | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL... |
| CVE-2026-63309 | MEDIUM | 4.3 | — | Jul 17, 2026 | SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to... |
| CVE-2026-63308 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template help... |
| CVE-2026-49216 | MEDIUM | 5.4 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/... |
| CVE-2026-49215 | MEDIUM | 5.4 | 0.2% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventList... |
| CVE-2026-49210 | MEDIUM | 6.1 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\Child... |
| CVE-2026-49209 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller... |
| CVE-2026-49208 | MEDIUM | 5.3 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as Date... |
| CVE-2026-44722 | MEDIUM | 6.2 | — | Jul 17, 2026 | pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python... |
| CVE-2026-21764 | MEDIUM | 4.3 | 0.2% | Jul 17, 2026 | HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric... |
| CVE-2026-21762 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag... |
| CVE-2026-21761 | MEDIUM | 5.4 | 0.1% | Jul 17, 2026 | HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may ... |
| CVE-2026-21760 | MEDIUM | 4.6 | 0.1% | Jul 17, 2026 | HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a... |
| CVE-2026-16108 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible... |
| CVE-2026-16106 | MEDIUM | 4.9 | 0.2% | Jul 17, 2026 | A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when... |
| CVE-2026-16104 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engi... |
| CVE-2026-16103 | MEDIUM | 4.3 | 0.2% | Jul 17, 2026 | A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher... |
| CVE-2026-16093 | MEDIUM | 5.4 | 0.2% | Jul 17, 2026 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them... |
| CVE-2026-11763 | MEDIUM | 6.5 | — | Jul 17, 2026 | Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D ... |
| CVE-2026-9537 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode()... |
| CVE-2026-63098 | MEDIUM | 6.9 | 0.2% | Jul 17, 2026 | TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated atta... |
| CVE-2026-63097 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/rout... |
| CVE-2026-63096 | MEDIUM | 6.9 | — | Jul 17, 2026 | Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to ca... |
| CVE-2026-58149 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking i... |
| CVE-2026-15783 | MEDIUM | 5.3 | — | Jul 17, 2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now