2026 CVE Vulnerabilities
43,657 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57896 | MEDIUM | 6.9 | 0.1% | Jul 16, 2026 | An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti... |
| CVE-2026-36425 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user... |
| CVE-2026-33731 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/Aut... |
| CVE-2026-62299 | MEDIUM | 5.3 | 0.3% | Jul 16, 2026 | CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an ... |
| CVE-2026-61718 | MEDIUM | 5.4 | 0.3% | Jul 16, 2026 | bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb w... |
| CVE-2026-60140 | MEDIUM | 6.9 | 0.1% | Jul 16, 2026 | An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti... |
| CVE-2026-54728 | MEDIUM | 6.1 | 0.2% | Jul 16, 2026 | bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb ... |
| CVE-2026-15449 | MEDIUM | 5.8 | 0.1% | Jul 16, 2026 | A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC... |
| CVE-2026-53536 | MEDIUM | 5.3 | 0.2% | Jul 16, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endp... |
| CVE-2026-53535 | MEDIUM | 5.9 | 0.6% | Jul 16, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf... |
| CVE-2026-47089 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces... |
| CVE-2026-47085 | MEDIUM | 4 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk... |
| CVE-2026-47084 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An aut... |
| CVE-2026-47083 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u... |
| CVE-2026-47082 | MEDIUM | 5.4 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-ma... |
| CVE-2026-46514 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword... |
| CVE-2026-46404 | MEDIUM | 6.8 | 0.3% | Jul 16, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly res... |
| CVE-2026-46378 | MEDIUM | 6.2 | 0.1% | Jul 16, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1... |
| CVE-2026-46377 | MEDIUM | 6.2 | 0.1% | Jul 16, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1... |
| CVE-2026-46338 | MEDIUM | 4.3 | 0.3% | Jul 16, 2026 | PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.... |
| CVE-2026-46341 | MEDIUM | 6.1 | 0.2% | Jul 16, 2026 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation... |
| CVE-2026-44970 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_call... |
| CVE-2026-44968 | MEDIUM | 6.3 | 0.1% | Jul 16, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/... |
| CVE-2026-15737 | MEDIUM | 5.7 | 0.2% | Jul 16, 2026 | AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on t... |
| CVE-2026-6511 | MEDIUM | 6.8 | — | Jul 16, 2026 | During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now