2026 CVE Vulnerabilities
44,088 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15792 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. |
| CVE-2026-15791 | HIGH | 7.5 | 0.1% | Jul 21, 2026 | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The acti... |
| CVE-2026-15789 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-contro... |
| CVE-2026-15724 | HIGH | 8.7 | 0.3% | Jul 21, 2026 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user ... |
| CVE-2026-15432 | HIGH | 8.2 | — | Jul 21, 2026 | When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time compar... |
| CVE-2026-47394 | HIGH | 8.7 | — | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is in... |
| CVE-2026-8933 | HIGH | 7.8 | — | Jul 21, 2026 | A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by ... |
| CVE-2026-65052 | HIGH | 8.7 | 0.3% | Jul 21, 2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows un... |
| CVE-2026-65050 | HIGH | 7.1 | 0.3% | Jul 21, 2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callb... |
| CVE-2026-59851 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the... |
| CVE-2026-59850 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok... |
| CVE-2026-59849 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clien... |
| CVE-2026-46681 | HIGH | 7.2 | 0.3% | Jul 21, 2026 | @nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps fu... |
| CVE-2026-15226 | HIGH | 8.4 | — | Jul 21, 2026 | A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler ... |
| CVE-2026-59847 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively re... |
| CVE-2026-16447 | HIGH | 7.3 | 0.7% | Jul 21, 2026 | A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader... |
| CVE-2026-16445 | HIGH | 7.5 | 1.0% | Jul 21, 2026 | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia... |
| CVE-2026-16409 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16405 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR... |
| CVE-2026-16404 | HIGH | 7.4 | 0.2% | Jul 21, 2026 | Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153. |
| CVE-2026-16401 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird ... |
| CVE-2026-16400 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16399 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16398 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. |
| CVE-2026-16396 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now