2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47199 | LOW | 2.3 | 0.4% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT I... |
| CVE-2026-13235 | LOW | 3.3 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects ... |
| CVE-2026-13233 | LOW | 3.3 | 0.2% | Jul 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issu... |
| CVE-2026-13232 | LOW | 3.1 | 0.2% | Jul 10, 2026 | Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing.... |
| CVE-2026-11909 | LOW | 3.3 | 0.2% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examp... |
| CVE-2026-55671 | LOW | 2.3 | 0.3% | Jul 10, 2026 | ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification chan... |
| CVE-2026-55670 | LOW | 2.3 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the... |
| CVE-2026-59180 | LOW | 3.1 | — | Jul 10, 2026 | Apprise is an open source library which allows you to send a notification to almost all of the most popular notification... |
| CVE-2026-55783 | LOW | 2.4 | — | Jul 10, 2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-hous... |
| CVE-2026-55782 | LOW | 2.4 | 0.1% | Jul 10, 2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly a... |
| CVE-2026-55781 | LOW | 2.4 | — | Jul 10, 2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS i... |
| CVE-2026-55780 | LOW | 2.4 | 0.1% | Jul 10, 2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-f... |
| CVE-2026-59791 | LOW | 3.5 | — | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible |
| CVE-2026-56813 | LOW | 2.1 | — | Jul 10, 2026 | Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject ... |
| CVE-2026-58225 | LOW | 2.1 | — | Jul 10, 2026 | SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject... |
| CVE-2026-15028 | LOW | 3.9 | 0.2% | Jul 10, 2026 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a sp... |
| CVE-2026-15326 | LOW | 3.8 | 0.4% | Jul 10, 2026 | A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the f... |
| CVE-2026-15321 | LOW | 2.4 | 0.2% | Jul 10, 2026 | A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/... |
| CVE-2026-15311 | LOW | 3.5 | 0.2% | Jul 10, 2026 | A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function Ma... |
| CVE-2026-15276 | LOW | 3.3 | 0.1% | Jul 9, 2026 | A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metad... |
| CVE-2026-15274 | LOW | 3.3 | 0.1% | Jul 9, 2026 | A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v74... |
| CVE-2026-59215 | LOW | 3.1 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread pa... |
| CVE-2026-15194 | LOW | 3.3 | — | Jul 9, 2026 | A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/co... |
| CVE-2026-15185 | LOW | 3.3 | — | Jul 9, 2026 | A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools... |
| CVE-2026-15184 | LOW | 3.3 | — | Jul 9, 2026 | A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now