2026 CVE Vulnerabilities
44,991 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54340 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state am... |
| CVE-2026-39359 | HIGH | 7.5 | 0.2% | Jul 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through ... |
| CVE-2026-34150 | HIGH | 7.5 | 0.2% | Jul 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and abov... |
| CVE-2026-33434 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and abov... |
| CVE-2026-44453 | HIGH | 7.5 | 0.3% | Jul 16, 2026 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Deni... |
| CVE-2026-44436 | HIGH | 7.5 | 0.3% | Jul 16, 2026 | Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b... |
| CVE-2026-44435 | HIGH | 7.5 | 0.3% | Jul 16, 2026 | Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 93... |
| CVE-2026-44433 | HIGH | 7.5 | 0.2% | Jul 16, 2026 | Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b... |
| CVE-2026-43978 | HIGH | 8.1 | 0.2% | Jul 16, 2026 | wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their sess... |
| CVE-2026-43977 | HIGH | 7.5 | 0.2% | Jul 16, 2026 | wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth... |
| CVE-2026-59117 | HIGH | 7.5 | 0.4% | Jul 16, 2026 | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. |
| CVE-2026-58598 | HIGH | 7 | 0.2% | Jul 16, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all... |
| CVE-2026-57077 | HIGH | 7.7 | 0.2% | Jul 16, 2026 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In t... |
| CVE-2026-57076 | HIGH | 7.8 | 0.2% | Jul 16, 2026 | YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key i... |
| CVE-2026-53411 | HIGH | 7 | 0.1% | Jul 16, 2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl... |
| CVE-2026-45368 | HIGH | 8.4 | 0.3% | Jul 16, 2026 | Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for ... |
| CVE-2026-44177 | HIGH | 8.8 | 0.5% | Jul 16, 2026 | Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correct... |
| CVE-2026-44175 | HIGH | 8.5 | 0.3% | Jul 16, 2026 | Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize... |
| CVE-2026-44174 | HIGH | 8.7 | 0.3% | Jul 16, 2026 | Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes... |
| CVE-2026-55173 | HIGH | 8.1 | 3.4% | Jul 16, 2026 | WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because ... |
| CVE-2026-53410 | HIGH | 7 | 0.1% | Jul 16, 2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl... |
| CVE-2026-53409 | HIGH | 7.8 | 0.2% | Jul 16, 2026 | Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct ... |
| CVE-2026-44023 | HIGH | 8.6 | 0.3% | Jul 16, 2026 | Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.... |
| CVE-2026-44019 | HIGH | 8.1 | 0.2% | Jul 16, 2026 | Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.... |
| CVE-2026-33692 | HIGH | 7.5 | 0.5% | Jul 16, 2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now