2026 CVE Vulnerabilities
44,013 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55464 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize jav... |
| CVE-2026-53449 | MEDIUM | 6 | 0.2% | Jul 10, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI co... |
| CVE-2026-15146 | MEDIUM | 5.9 | 0.1% | Jul 10, 2026 | GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malici... |
| CVE-2026-57476 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio... |
| CVE-2026-57475 | MEDIUM | 6.9 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed ... |
| CVE-2026-57474 | MEDIUM | 6.9 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accept... |
| CVE-2026-56666 | MEDIUM | 4.8 | 0.2% | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch... |
| CVE-2026-56665 | MEDIUM | 4.2 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity m... |
| CVE-2026-56664 | MEDIUM | 4.2 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov... |
| CVE-2026-59193 | MEDIUM | 4.9 | — | Jul 10, 2026 | Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by ... |
| CVE-2026-59154 | MEDIUM | 4.3 | — | Jul 10, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct... |
| CVE-2026-58493 | MEDIUM | 5.1 | 0.3% | Jul 10, 2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by dir... |
| CVE-2026-57167 | MEDIUM | 5.1 | — | Jul 10, 2026 | PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, server-side-rendered video watch pages em... |
| CVE-2026-55890 | MEDIUM | 4.8 | — | Jul 10, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media ... |
| CVE-2026-55885 | MEDIUM | 6.8 | 0.2% | Jul 10, 2026 | Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download ... |
| CVE-2026-55669 | MEDIUM | 4.2 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov... |
| CVE-2026-3251 | MEDIUM | 6.4 | — | Jul 10, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul... |
| CVE-2026-15377 | MEDIUM | 4.3 | 0.3% | Jul 10, 2026 | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown fun... |
| CVE-2026-15376 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/... |
| CVE-2026-8595 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that ex... |
| CVE-2026-46388 | MEDIUM | 4.4 | — | Jul 10, 2026 | osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unpr... |
| CVE-2026-15375 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /ca... |
| CVE-2026-15374 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/rol... |
| CVE-2026-15373 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the... |
| CVE-2026-61492 | MEDIUM | 6.1 | — | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now