2026 CVE Vulnerabilities
44,969 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47871 | HIGH | 8.8 | 0.9% | Jul 18, 2026 | VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, au... |
| CVE-2026-47870 | HIGH | 7.1 | 0.3% | Jul 18, 2026 | VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network acce... |
| CVE-2026-47869 | HIGH | 8.7 | 0.7% | Jul 18, 2026 | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network acc... |
| CVE-2026-47868 | HIGH | 7.8 | 0.1% | Jul 18, 2026 | VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be ... |
| CVE-2026-47867 | HIGH | 8.7 | 0.7% | Jul 18, 2026 | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be abl... |
| CVE-2026-47866 | HIGH | 8.3 | 0.4% | Jul 18, 2026 | VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a l... |
| CVE-2026-16084 | HIGH | 7.3 | 0.4% | Jul 18, 2026 | A weakness has been identified in Sipeed PicoClaw up to 0.2.9. This impacts the function web_fetch of the file pkg/tools... |
| CVE-2026-56741 | HIGH | 7.5 | 0.5% | Jul 17, 2026 | JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote... |
| CVE-2026-56740 | HIGH | 7.5 | 0.5% | Jul 17, 2026 | JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote... |
| CVE-2026-56171 | HIGH | 7.5 | 0.6% | Jul 17, 2026 | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disc... |
| CVE-2026-49485 | HIGH | 7.5 | 0.7% | Jul 17, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 ... |
| CVE-2026-54498 | HIGH | 8.7 | 0.3% | Jul 17, 2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4... |
| CVE-2026-54466 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions ... |
| CVE-2026-53727 | HIGH | 8.9 | 0.5% | Jul 17, 2026 | css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb,... |
| CVE-2026-52584 | HIGH | 7.1 | 0.1% | Jul 17, 2026 | Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via ... |
| CVE-2026-52203 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter. |
| CVE-2026-50274 | HIGH | 7.5 | 0.8% | Jul 17, 2026 | Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monit... |
| CVE-2026-50272 | HIGH | 7.5 | 0.8% | Jul 17, 2026 | dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/bagga... |
| CVE-2026-50271 | HIGH | 7.5 | 0.8% | Jul 17, 2026 | Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C bagga... |
| CVE-2026-45784 | HIGH | 7.1 | 0.1% | Jul 17, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::ciph... |
| CVE-2026-44891 | HIGH | 7.5 | 0.7% | Jul 17, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2... |
| CVE-2026-13445 | HIGH | 8.1 | 0.2% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an... |
| CVE-2026-8056 | HIGH | 8.8 | 0.3% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API... |
| CVE-2026-7872 | HIGH | 8.1 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing... |
| CVE-2026-7755 | HIGH | 8.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcemen... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now