2026 CVE Vulnerabilities
44,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9171 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused ... |
| CVE-2026-58195 | HIGH | 8.8 | 0.5% | Jul 17, 2026 | Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone... |
| CVE-2026-53712 | HIGH | 8.2 | 0.3% | Jul 17, 2026 | SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L... |
| CVE-2026-52746 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toM... |
| CVE-2026-49835 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middle... |
| CVE-2026-45309 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to... |
| CVE-2026-45162 | HIGH | 8 | 0.6% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc... |
| CVE-2026-9762 | HIGH | 7.8 | 0.2% | Jul 17, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under u... |
| CVE-2026-50273 | HIGH | 7.5 | — | Jul 17, 2026 | Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing librarie... |
| CVE-2026-9588 | HIGH | 7 | — | Jul 17, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicem... |
| CVE-2026-9587 | HIGH | 7.1 | — | Jul 17, 2026 | An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file ... |
| CVE-2026-9585 | HIGH | 8.6 | — | Jul 17, 2026 | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.... |
| CVE-2026-63307 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{i... |
| CVE-2026-63101 | HIGH | 8.7 | — | Jul 17, 2026 | Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers t... |
| CVE-2026-57860 | HIGH | 7.8 | — | Jul 17, 2026 | ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined i... |
| CVE-2026-49212 | HIGH | 7.5 | 0.2% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\Liv... |
| CVE-2026-49211 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\En... |
| CVE-2026-12691 | HIGH | 7.5 | — | Jul 17, 2026 | Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authenticat... |
| CVE-2026-63100 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role u... |
| CVE-2026-63099 | HIGH | 7.1 | — | Jul 17, 2026 | TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints t... |
| CVE-2026-63095 | HIGH | 7.1 | — | Jul 17, 2026 | Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any... |
| CVE-2026-60025 | HIGH | 8.8 | 0.1% | Jul 17, 2026 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking p... |
| CVE-2026-58148 | HIGH | 8.7 | 0.3% | Jul 17, 2026 | Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension... |
| CVE-2026-15343 | HIGH | 8.6 | — | Jul 17, 2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code executio... |
| CVE-2026-14871 | HIGH | 7.1 | — | Jul 17, 2026 | osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Obje... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now