2026 CVE Vulnerabilities
44,991 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11889 | HIGH | 7.1 | 0.2% | Jul 16, 2026 | SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation at... |
| CVE-2026-63397 | HIGH | 7.1 | 0.3% | Jul 16, 2026 | remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed t... |
| CVE-2026-62963 | HIGH | 8.7 | 0.3% | Jul 16, 2026 | Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket tr... |
| CVE-2026-62309 | HIGH | 7.5 | 0.4% | Jul 16, 2026 | CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when... |
| CVE-2026-62290 | HIGH | 7.3 | 0.1% | Jul 16, 2026 | cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc... |
| CVE-2026-61389 | HIGH | 7.3 | 0.1% | Jul 16, 2026 | An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt... |
| CVE-2026-60063 | HIGH | 7.3 | 0.1% | Jul 16, 2026 | An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt... |
| CVE-2026-55629 | HIGH | 8.7 | 0.5% | Jul 16, 2026 | Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cg... |
| CVE-2026-49998 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verif... |
| CVE-2026-44982 | HIGH | 7.2 | 0.2% | Jul 16, 2026 | CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRe... |
| CVE-2026-44981 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/... |
| CVE-2026-15352 | HIGH | 8.2 | 0.4% | Jul 16, 2026 | A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the a... |
| CVE-2026-46513 | HIGH | 7.4 | 0.3% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by T... |
| CVE-2026-46353 | HIGH | 8.1 | 0.3% | Jul 16, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a... |
| CVE-2026-46351 | HIGH | 8.1 | 0.3% | Jul 16, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values wit... |
| CVE-2026-46687 | HIGH | 7.7 | 0.3% | Jul 16, 2026 | Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-t... |
| CVE-2026-46686 | HIGH | 8.5 | 0.3% | Jul 16, 2026 | Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword p... |
| CVE-2026-46336 | HIGH | 7.1 | 0.3% | Jul 16, 2026 | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ... |
| CVE-2026-9046 | HIGH | 7.3 | — | Jul 16, 2026 | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications... |
| CVE-2026-63088 | HIGH | 8.6 | — | Jul 16, 2026 | stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-... |
| CVE-2026-63086 | HIGH | 8.6 | — | Jul 16, 2026 | text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat... |
| CVE-2026-63085 | HIGH | 8.8 | 0.4% | Jul 16, 2026 | Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticate... |
| CVE-2026-45576 | HIGH | 7.5 | 0.4% | Jul 16, 2026 | zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores at... |
| CVE-2026-45367 | HIGH | 7.5 | 0.5% | Jul 16, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7,... |
| CVE-2026-45325 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now