2026 CVE Vulnerabilities
43,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56375 | MEDIUM | 4.8 | — | Jul 15, 2026 | ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers ca... |
| CVE-2026-56353 | MEDIUM | 6.3 | 0.2% | Jul 15, 2026 | n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configu... |
| CVE-2026-56352 | MEDIUM | 6.4 | — | Jul 15, 2026 | n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, ... |
| CVE-2026-56349 | MEDIUM | 6.3 | — | Jul 15, 2026 | n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypa... |
| CVE-2026-40633 | MEDIUM | 5.5 | — | Jul 15, 2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sen... |
| CVE-2026-49501 | MEDIUM | 6.7 | 0.2% | Jul 15, 2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Pri... |
| CVE-2026-11580 | MEDIUM | 5.5 | 0.1% | Jul 15, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capab... |
| CVE-2026-11579 | MEDIUM | 5.3 | 0.2% | Jul 15, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload ... |
| CVE-2026-15030 | MEDIUM | 5.6 | 0.1% | Jul 15, 2026 | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows ... |
| CVE-2026-11851 | MEDIUM | 5.9 | 0.3% | Jul 15, 2026 | Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of ... |
| CVE-2026-9770 | MEDIUM | 5.3 | 0.3% | Jul 15, 2026 | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is s... |
| CVE-2026-13230 | MEDIUM | 6.5 | 0.3% | Jul 15, 2026 | An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechan... |
| CVE-2026-36035 | MEDIUM | 6.5 | 0.2% | Jul 14, 2026 | Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Ser... |
| CVE-2026-15753 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown ... |
| CVE-2026-15751 | MEDIUM | 5.3 | 0.1% | Jul 14, 2026 | A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is th... |
| CVE-2026-59732 | MEDIUM | 5 | 0.2% | Jul 14, 2026 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1... |
| CVE-2026-48357 | MEDIUM | 6.2 | 0.2% | Jul 14, 2026 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application... |
| CVE-2026-48354 | MEDIUM | 6.2 | 0.2% | Jul 14, 2026 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati... |
| CVE-2026-48353 | MEDIUM | 5.5 | 0.2% | Jul 14, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst... |
| CVE-2026-48312 | MEDIUM | 6.8 | 0.2% | Jul 14, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur... |
| CVE-2026-48302 | MEDIUM | 6.2 | 0.2% | Jul 14, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de... |
| CVE-2026-48298 | MEDIUM | 6.2 | 0.2% | Jul 14, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a... |
| CVE-2026-48296 | MEDIUM | 6.2 | 0.2% | Jul 14, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a... |
| CVE-2026-47732 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a ... |
| CVE-2026-47730 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now