2026 CVE Vulnerabilities
43,657 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55548 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/sr... |
| CVE-2026-55407 | MEDIUM | 6.3 | — | Jul 16, 2026 | Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the dec... |
| CVE-2026-55406 | MEDIUM | 5.9 | — | Jul 16, 2026 | Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a sound... |
| CVE-2026-50012 | MEDIUM | 5.5 | 2.3% | Jul 16, 2026 | Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handli... |
| CVE-2026-47751 | MEDIUM | 5.3 | 0.4% | Jul 16, 2026 | Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to... |
| CVE-2026-47729 | MEDIUM | 6.5 | 1.9% | Jul 16, 2026 | Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in t... |
| CVE-2026-45795 | MEDIUM | 5.3 | — | Jul 16, 2026 | The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server ac... |
| CVE-2026-45612 | MEDIUM | 5.5 | — | Jul 16, 2026 | rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can... |
| CVE-2026-44595 | MEDIUM | 4.3 | 1.0% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGrou... |
| CVE-2026-10590 | MEDIUM | 6.7 | — | Jul 16, 2026 | A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrar... |
| CVE-2026-10589 | MEDIUM | 6.8 | — | Jul 16, 2026 | A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Manageme... |
| CVE-2026-10588 | MEDIUM | 6.7 | — | Jul 16, 2026 | A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management... |
| CVE-2026-10587 | MEDIUM | 6.8 | — | Jul 16, 2026 | A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management setting... |
| CVE-2026-63082 | MEDIUM | 5.4 | — | Jul 16, 2026 | Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that a... |
| CVE-2026-63081 | MEDIUM | 5.4 | 0.1% | Jul 16, 2026 | Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability ... |
| CVE-2026-57205 | MEDIUM | 4.3 | — | Jul 16, 2026 | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions... |
| CVE-2026-55440 | MEDIUM | 6.5 | — | Jul 16, 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND... |
| CVE-2026-54568 | MEDIUM | 4.3 | — | Jul 16, 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c... |
| CVE-2026-12379 | MEDIUM | 6.8 | — | Jul 16, 2026 | An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard... |
| CVE-2026-59237 | MEDIUM | 6.9 | — | Jul 16, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Pro... |
| CVE-2026-56456 | MEDIUM | 5.3 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently ... |
| CVE-2026-35143 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" ... |
| CVE-2026-35141 | MEDIUM | 5.3 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce... |
| CVE-2026-9494 | MEDIUM | 5.5 | — | Jul 16, 2026 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The cli... |
| CVE-2026-12391 | MEDIUM | 5 | — | Jul 16, 2026 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) with... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now