2026 CVE Vulnerabilities
43,769 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50182 | MEDIUM | 6.1 | 0.2% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerabil... |
| CVE-2026-38974 | MEDIUM | 5.3 | 0.1% | Jul 15, 2026 | Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. |
| CVE-2026-38754 | MEDIUM | 5.1 | 0.2% | Jul 15, 2026 | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv... |
| CVE-2026-26719 | MEDIUM | 6.1 | 0.4% | Jul 15, 2026 | Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a cra... |
| CVE-2026-62361 | MEDIUM | 5.5 | 0.2% | Jul 15, 2026 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscrib... |
| CVE-2026-56678 | MEDIUM | 6.4 | 0.2% | Jul 15, 2026 | 9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key... |
| CVE-2026-55608 | MEDIUM | 5.4 | 0.3% | Jul 15, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-55410 | MEDIUM | 6.7 | 0.4% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-55399 | MEDIUM | 4.3 | 0.2% | Jul 15, 2026 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with vali... |
| CVE-2026-52888 | MEDIUM | 6.8 | 0.3% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.... |
| CVE-2026-38753 | MEDIUM | 4.9 | 0.3% | Jul 15, 2026 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv... |
| CVE-2026-33684 | MEDIUM | 5.3 | 0.3% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded ... |
| CVE-2026-33445 | MEDIUM | 5.9 | 0.3% | Jul 15, 2026 | CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate ... |
| CVE-2026-56743 | MEDIUM | 5.4 | 0.2% | Jul 15, 2026 | Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy s... |
| CVE-2026-49867 | MEDIUM | 6.3 | 0.3% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources le... |
| CVE-2026-45737 | MEDIUM | 6.5 | 0.3% | Jul 15, 2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Ar... |
| CVE-2026-40953 | MEDIUM | 4.4 | 0.1% | Jul 15, 2026 | CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers... |
| CVE-2026-33443 | MEDIUM | 5.9 | 0.2% | Jul 15, 2026 | CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledg... |
| CVE-2026-62947 | MEDIUM | 4.9 | 0.4% | Jul 15, 2026 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io aut... |
| CVE-2026-62355 | MEDIUM | 5.4 | — | Jul 15, 2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Rea... |
| CVE-2026-62353 | MEDIUM | 5.4 | — | Jul 15, 2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/p... |
| CVE-2026-62348 | MEDIUM | 5.4 | 0.2% | Jul 15, 2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allo... |
| CVE-2026-54443 | MEDIUM | 5.9 | — | Jul 15, 2026 | Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssF... |
| CVE-2026-49988 | MEDIUM | 6.8 | 0.2% | Jul 15, 2026 | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_... |
| CVE-2026-26032 | MEDIUM | 5.4 | — | Jul 15, 2026 | The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now