2026 CVE Vulnerabilities
44,807 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64206 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before tak... |
| CVE-2026-64191 | HIGH | 7.8 | 0.1% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid ... |
| CVE-2026-64189 | HIGH | 7.8 | 0.1% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_... |
| CVE-2026-64188 | HIGH | 7.8 | 0.1% | Jul 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix endpoint use-after-free i... |
| CVE-2026-58484 | HIGH | 7.1 | 0.1% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()`... |
| CVE-2026-54538 | HIGH | 7.5 | 0.7% | Jul 20, 2026 | xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to pr... |
| CVE-2026-46701 | HIGH | 7.6 | 0.2% | Jul 20, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an e... |
| CVE-2026-46555 | HIGH | 7.7 | 0.2% | Jul 20, 2026 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp mes... |
| CVE-2026-44178 | HIGH | 8.8 | 0.9% | Jul 20, 2026 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within t... |
| CVE-2026-40187 | HIGH | 8.6 | 0.9% | Jul 20, 2026 | In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) ... |
| CVE-2026-39879 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb... |
| CVE-2026-39385 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment vali... |
| CVE-2026-35591 | HIGH | 7 | 0.1% | Jul 20, 2026 | libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before an... |
| CVE-2026-33327 | HIGH | 7 | 0.1% | Jul 20, 2026 | libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and includ... |
| CVE-2026-32825 | HIGH | 7.3 | 0.3% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-32824 | HIGH | 7.3 | 0.3% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-32821 | HIGH | 8.1 | 0.2% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-32820 | HIGH | 7.5 | 0.6% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-32806 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-63429 | HIGH | 8.6 | 0.3% | Jul 20, 2026 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no ... |
| CVE-2026-46415 | HIGH | 8.2 | 0.2% | Jul 20, 2026 | The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the clien... |
| CVE-2026-45713 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.M... |
| CVE-2026-45711 | HIGH | 8.2 | 0.2% | Jul 20, 2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <ou... |
| CVE-2026-32807 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat... |
| CVE-2026-27823 | HIGH | 8.7 | 1.0% | Jul 20, 2026 | A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an auth... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now