2026 CVE Vulnerabilities
44,067 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39243 | MEDIUM | 5.5 | 0.2% | Jul 9, 2026 | decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and ... |
| CVE-2026-33803 | MEDIUM | 6.9 | 0.4% | Jul 9, 2026 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve... |
| CVE-2026-33802 | MEDIUM | 6.8 | 0.1% | Jul 9, 2026 | A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated... |
| CVE-2026-60120 | MEDIUM | 5.4 | 0.2% | Jul 9, 2026 | Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows... |
| CVE-2026-33799 | MEDIUM | 5.3 | 0.4% | Jul 9, 2026 | An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows... |
| CVE-2026-31267 | MEDIUM | 5.7 | 0.2% | Jul 9, 2026 | Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. ... |
| CVE-2026-21901 | MEDIUM | 6.7 | 0.2% | Jul 9, 2026 | A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolve... |
| CVE-2026-0277 | MEDIUM | 5.9 | 0.1% | Jul 9, 2026 | An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a ma... |
| CVE-2026-0275 | MEDIUM | 6.7 | 0.1% | Jul 9, 2026 | A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administ... |
| CVE-2026-59149 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is ... |
| CVE-2026-58198 | MEDIUM | 5.5 | — | Jul 9, 2026 | ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrai... |
| CVE-2026-55590 | MEDIUM | 6.1 | 0.6% | Jul 9, 2026 | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior ... |
| CVE-2026-54695 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1... |
| CVE-2026-54004 | MEDIUM | 6.3 | 0.3% | Jul 9, 2026 | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enab... |
| CVE-2026-50188 | MEDIUM | 6.9 | 0.3% | Jul 9, 2026 | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Htt... |
| CVE-2026-49274 | MEDIUM | 5.3 | 0.3% | Jul 9, 2026 | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with role... |
| CVE-2026-0285 | MEDIUM | 4.9 | 0.2% | Jul 9, 2026 | A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated admini... |
| CVE-2026-0282 | MEDIUM | 6.5 | 0.2% | Jul 9, 2026 | A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network ac... |
| CVE-2026-0279 | MEDIUM | 6.1 | 0.3% | Jul 9, 2026 | Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, Global... |
| CVE-2026-61344 | MEDIUM | 6.9 | 0.3% | Jul 9, 2026 | The Superior Court of California Hearing Reminder Service at https://www.hrs.courts.ca.gov exposes an API endpoint that ... |
| CVE-2026-59817 | MEDIUM | 5.3 | 0.3% | Jul 9, 2026 | Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed a... |
| CVE-2026-43752 | MEDIUM | 4.9 | 0.3% | Jul 9, 2026 | An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicio... |
| CVE-2026-15204 | MEDIUM | 5.5 | 0.5% | Jul 9, 2026 | A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerab... |
| CVE-2026-15202 | MEDIUM | 4.3 | — | Jul 9, 2026 | A security vulnerability has been detected in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp/yzm... |
| CVE-2026-15195 | MEDIUM | 6.3 | — | Jul 9, 2026 | A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Po... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now