2026 CVE Vulnerabilities
43,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33213 | MEDIUM | 6.1 | — | Jul 15, 2026 | Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's a... |
| CVE-2026-59838 | MEDIUM | 4.8 | — | Jul 15, 2026 | A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.... |
| CVE-2026-58559 | MEDIUM | 6.5 | — | Jul 15, 2026 | DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availabilit... |
| CVE-2026-58557 | MEDIUM | 4.8 | — | Jul 15, 2026 | Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availab... |
| CVE-2026-58556 | MEDIUM | 5.1 | — | Jul 15, 2026 | Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affe... |
| CVE-2026-58555 | MEDIUM | 6.6 | — | Jul 15, 2026 | Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect ava... |
| CVE-2026-58554 | MEDIUM | 6.6 | — | Jul 15, 2026 | Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-58553 | MEDIUM | 4 | — | Jul 15, 2026 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2026-58552 | MEDIUM | 5.1 | — | Jul 15, 2026 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2026-58551 | MEDIUM | 5.1 | — | Jul 15, 2026 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2026-58550 | MEDIUM | 4 | — | Jul 15, 2026 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2026-58549 | MEDIUM | 4 | — | Jul 15, 2026 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2026-46459 | MEDIUM | 5.3 | — | Jul 15, 2026 | ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows a... |
| CVE-2026-15779 | MEDIUM | 6.1 | — | Jul 15, 2026 | A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directo... |
| CVE-2026-61871 | MEDIUM | 6.3 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocatio... |
| CVE-2026-61868 | MEDIUM | 6.3 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when openin... |
| CVE-2026-61860 | MEDIUM | 6.3 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initializati... |
| CVE-2026-61859 | MEDIUM | 4.8 | 0.1% | Jul 15, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operatio... |
| CVE-2026-61453 | MEDIUM | 6.1 | — | Jul 15, 2026 | Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detec... |
| CVE-2026-61452 | MEDIUM | 6.9 | — | Jul 15, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where... |
| CVE-2026-60087 | MEDIUM | 6.9 | — | Jul 15, 2026 | PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals ... |
| CVE-2026-59259 | MEDIUM | 6.5 | 0.3% | Jul 15, 2026 | n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling... |
| CVE-2026-59254 | MEDIUM | 6.3 | — | Jul 15, 2026 | n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in wo... |
| CVE-2026-59236 | MEDIUM | 6.9 | — | Jul 15, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, Pro... |
| CVE-2026-56764 | MEDIUM | 6.3 | — | Jul 15, 2026 | Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-consta... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now