2026 CVE Vulnerabilities
44,088 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52476 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPage... |
| CVE-2026-52474 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file. |
| CVE-2026-47697 | HIGH | 7.1 | 0.2% | Jul 21, 2026 | Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). ... |
| CVE-2026-47695 | HIGH | 7.1 | 0.3% | Jul 21, 2026 | CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.... |
| CVE-2026-47690 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to ... |
| CVE-2026-47688 | HIGH | 8.2 | 0.2% | Jul 21, 2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.... |
| CVE-2026-47687 | HIGH | 8.7 | 0.2% | Jul 21, 2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.... |
| CVE-2026-47685 | HIGH | 8.7 | 0.2% | Jul 21, 2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.... |
| CVE-2026-47237 | HIGH | 8 | 0.3% | Jul 21, 2026 | Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to versio... |
| CVE-2026-44879 | HIGH | 7.2 | 1.5% | Jul 21, 2026 | A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote atta... |
| CVE-2026-44878 | HIGH | 7.2 | 0.3% | Jul 21, 2026 | A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated r... |
| CVE-2026-30633 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools... |
| CVE-2026-16317 | HIGH | 8.3 | 0.2% | Jul 21, 2026 | Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-mi... |
| CVE-2026-64880 | HIGH | 7.1 | 0.2% | Jul 21, 2026 | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper ... |
| CVE-2026-59146 | HIGH | 7.8 | 0.2% | Jul 21, 2026 | Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, lin... |
| CVE-2026-56852 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. |
| CVE-2026-50759 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instan... |
| CVE-2026-50758 | HIGH | 8.1 | 0.3% | Jul 21, 2026 | Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary c... |
| CVE-2026-50757 | HIGH | 7.8 | 0.4% | Jul 21, 2026 | Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary cod... |
| CVE-2026-50756 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-pro... |
| CVE-2026-47667 | HIGH | 7.5 | 0.4% | Jul 21, 2026 | CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field i... |
| CVE-2026-46600 | HIGH | 7.5 | 0.4% | Jul 21, 2026 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| CVE-2026-30632 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool. |
| CVE-2026-15957 | HIGH | 8.7 | 0.4% | Jul 21, 2026 | Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface ... |
| CVE-2026-63454 | HIGH | 7.2 | 0.5% | Jul 21, 2026 | An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now