2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59269 | LOW | 3.8 | 0.2% | Jul 9, 2026 | A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in ... |
| CVE-2026-54780 | LOW | 3.7 | 0.2% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-15115 | LOW | 3.3 | 0.1% | Jul 8, 2026 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed... |
| CVE-2026-15168 | LOW | 3.3 | 0.1% | Jul 8, 2026 | BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure |
| CVE-2026-6352 | LOW | 2.7 | 0.3% | Jul 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.... |
| CVE-2026-57481 | LOW | 2.3 | 0.4% | Jul 8, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a... |
| CVE-2026-55778 | LOW | 2.1 | 0.4% | Jul 8, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a... |
| CVE-2026-14967 | LOW | 3.1 | 0.2% | Jul 8, 2026 | BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory... |
| CVE-2026-14966 | LOW | 3.1 | 0.3% | Jul 8, 2026 | BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it fa... |
| CVE-2026-53480 | LOW | 2.7 | — | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-15041 | LOW | 3.7 | 0.3% | Jul 8, 2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for co... |
| CVE-2026-59153 | LOW | 2.1 | 0.2% | Jul 7, 2026 | Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve me... |
| CVE-2026-28378 | LOW | 2.7 | 0.1% | Jul 7, 2026 | The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organizatio... |
| CVE-2026-55592 | LOW | 3.9 | 0.3% | Jul 7, 2026 | Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and a... |
| CVE-2026-14935 | LOW | 3.7 | 0.1% | Jul 7, 2026 | A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverte... |
| CVE-2026-42201 | LOW | 3.3 | 0.2% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-27844 | LOW | 2.7 | 0.2% | Jul 7, 2026 | Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated... |
| CVE-2026-27790 | LOW | 2.7 | 0.2% | Jul 7, 2026 | Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by ... |
| CVE-2026-42172 | LOW | 3.1 | 0.2% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-42145 | LOW | 3.1 | 0.3% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34149 | LOW | 3.3 | 0.2% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-53640 | LOW | 2.3 | 0.2% | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff ac... |
| CVE-2026-43928 | LOW | 2.3 | 0.3% | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment... |
| CVE-2026-42148 | LOW | 3.8 | — | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34049 | LOW | 3.3 | — | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now