2026 CVE Vulnerabilities
44,973 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7755 | HIGH | 8.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcemen... |
| CVE-2026-7667 | HIGH | 8.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacke... |
| CVE-2026-54465 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to im... |
| CVE-2026-54463 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket pro... |
| CVE-2026-51833 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can ... |
| CVE-2026-50289 | HIGH | 8.8 | 1.1% | Jul 17, 2026 | systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is v... |
| CVE-2026-50197 | HIGH | 7.8 | 0.5% | Jul 17, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent... |
| CVE-2026-50163 | HIGH | 7.1 | 0.4% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 vali... |
| CVE-2026-50151 | HIGH | 7.5 | 0.5% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completeP... |
| CVE-2026-4942 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Tran... |
| CVE-2026-49852 | HIGH | 8.7 | 0.2% | Jul 17, 2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2026-49834 | HIGH | 7.5 | 0.1% | Jul 17, 2026 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransp... |
| CVE-2026-49284 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSA... |
| CVE-2026-48373 | HIGH | 7.8 | 0.2% | Jul 17, 2026 | Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i... |
| CVE-2026-45799 | HIGH | 7.5 | 0.5% | Jul 17, 2026 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArra... |
| CVE-2026-45704 | HIGH | 7.1 | 0.3% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses i... |
| CVE-2026-45260 | HIGH | 8.1 | 0.4% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV ass... |
| CVE-2026-44974 | HIGH | 7.7 | 0.3% | Jul 17, 2026 | @hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrenc... |
| CVE-2026-44739 | HIGH | 8.7 | 0.3% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigActi... |
| CVE-2026-16118 | HIGH | 7.1 | 0.1% | Jul 17, 2026 | A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the ... |
| CVE-2026-15322 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the ... |
| CVE-2026-14979 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ... |
| CVE-2026-14971 | HIGH | 7 | 0.1% | Jul 17, 2026 | IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attac... |
| CVE-2026-14499 | HIGH | 8.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elev... |
| CVE-2026-9171 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now