2026 CVE Vulnerabilities
43,188 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56193 | LOW | 3.3 | 0.4% | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
| CVE-2026-50678 | LOW | 3.3 | 0.3% | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
| CVE-2026-52841 | LOW | 3.1 | — | Jul 14, 2026 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/co... |
| CVE-2026-52840 | LOW | 2.7 | 0.2% | Jul 14, 2026 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `ap... |
| CVE-2026-52839 | LOW | 3.3 | 0.1% | Jul 14, 2026 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appoi... |
| CVE-2026-52838 | LOW | 2.6 | — | Jul 14, 2026 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custo... |
| CVE-2026-15690 | LOW | 3.1 | — | Jul 14, 2026 | A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesAr... |
| CVE-2026-15678 | LOW | 3.5 | 0.2% | Jul 14, 2026 | A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of t... |
| CVE-2026-44753 | LOW | 3.7 | 0.2% | Jul 14, 2026 | SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produ... |
| CVE-2026-15605 | LOW | 3.1 | 0.2% | Jul 13, 2026 | A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download... |
| CVE-2026-15594 | LOW | 3.7 | 0.3% | Jul 13, 2026 | A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the l... |
| CVE-2026-9820 | LOW | 3.8 | — | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams end... |
| CVE-2026-61971 | LOW | 2.7 | 0.3% | Jul 13, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-pictu... |
| CVE-2026-15532 | LOW | 2.4 | 0.2% | Jul 13, 2026 | A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processin... |
| CVE-2026-15528 | LOW | 3.3 | 0.1% | Jul 13, 2026 | A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file k... |
| CVE-2026-15526 | LOW | 3.3 | 0.1% | Jul 13, 2026 | A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProjectDeps of the file s... |
| CVE-2026-15524 | LOW | 3.3 | 0.1% | Jul 13, 2026 | A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects an unknown part of t... |
| CVE-2026-15505 | LOW | 3.5 | 0.2% | Jul 12, 2026 | A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra... |
| CVE-2026-61874 | LOW | 3.1 | 0.2% | Jul 12, 2026 | filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, all... |
| CVE-2026-61448 | LOW | 2.1 | 0.2% | Jul 11, 2026 | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and... |
| CVE-2026-55807 | LOW | 3.1 | 0.1% | Jul 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af... |
| CVE-2026-47199 | LOW | 2.3 | 0.4% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT I... |
| CVE-2026-13235 | LOW | 3.3 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects ... |
| CVE-2026-13233 | LOW | 3.3 | 0.2% | Jul 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issu... |
| CVE-2026-13232 | LOW | 3.1 | 0.2% | Jul 10, 2026 | Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now