2026 CVE Vulnerabilities
43,990 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55469 | MEDIUM | 6.5 | 0.4% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update p... |
| CVE-2026-55462 | MEDIUM | 4.3 | 0.3% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authoriz... |
| CVE-2026-55461 | MEDIUM | 6.1 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the ... |
| CVE-2026-55370 | MEDIUM | 6.4 | 0.2% | Jul 10, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verifi... |
| CVE-2026-54714 | MEDIUM | 6.1 | 0.3% | Jul 10, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SA... |
| CVE-2026-15295 | MEDIUM | 4.4 | 0.2% | Jul 10, 2026 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm... |
| CVE-2026-55843 | MEDIUM | 6.5 | 0.3% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission... |
| CVE-2026-55478 | MEDIUM | 5.4 | — | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether th... |
| CVE-2026-55476 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_... |
| CVE-2026-55474 | MEDIUM | 6.5 | — | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the rout... |
| CVE-2026-55472 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locati... |
| CVE-2026-55464 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize jav... |
| CVE-2026-53449 | MEDIUM | 6 | 0.2% | Jul 10, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI co... |
| CVE-2026-15146 | MEDIUM | 5.9 | 0.1% | Jul 10, 2026 | GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malici... |
| CVE-2026-57476 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio... |
| CVE-2026-57475 | MEDIUM | 6.9 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed ... |
| CVE-2026-57474 | MEDIUM | 6.9 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accept... |
| CVE-2026-56666 | MEDIUM | 4.8 | 0.2% | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch... |
| CVE-2026-56665 | MEDIUM | 4.2 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity m... |
| CVE-2026-56664 | MEDIUM | 4.2 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov... |
| CVE-2026-59193 | MEDIUM | 4.9 | — | Jul 10, 2026 | Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by ... |
| CVE-2026-59154 | MEDIUM | 4.3 | — | Jul 10, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct... |
| CVE-2026-58493 | MEDIUM | 5.1 | 0.3% | Jul 10, 2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by dir... |
| CVE-2026-57167 | MEDIUM | 5.1 | — | Jul 10, 2026 | PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages em... |
| CVE-2026-55890 | MEDIUM | 4.8 | — | Jul 10, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now