2026 CVE Vulnerabilities
44,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45313 | HIGH | 7.7 | 0.1% | Jul 15, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegist... |
| CVE-2026-36590 | HIGH | 7.5 | 0.3% | Jul 15, 2026 | An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in... |
| CVE-2026-62312 | HIGH | 8.8 | 0.7% | Jul 15, 2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitra... |
| CVE-2026-59950 | HIGH | 8.1 | 0.2% | Jul 15, 2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,... |
| CVE-2026-56679 | HIGH | 8.7 | 0.3% | Jul 15, 2026 | 9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body t... |
| CVE-2026-49353 | HIGH | 7.5 | 0.4% | Jul 15, 2026 | 9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate use... |
| CVE-2026-56742 | HIGH | 8.9 | 0.2% | Jul 15, 2026 | Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters usi... |
| CVE-2026-52870 | HIGH | 7.6 | 0.2% | Jul 15, 2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 unti... |
| CVE-2026-52869 | HIGH | 7.1 | 0.3% | Jul 15, 2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2,... |
| CVE-2026-50144 | HIGH | 7.1 | 0.1% | Jul 15, 2026 | ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434... |
| CVE-2026-50124 | HIGH | 7.1 | 0.3% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploadin... |
| CVE-2026-50030 | HIGH | 7.1 | 0.3% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetD... |
| CVE-2026-49445 | HIGH | 8.8 | 0.2% | Jul 15, 2026 | Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 funct... |
| CVE-2026-45738 | HIGH | 8.7 | 0.3% | Jul 15, 2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD us... |
| CVE-2026-45535 | HIGH | 8.7 | 0.2% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store atta... |
| CVE-2026-45533 | HIGH | 8.3 | 0.3% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can a... |
| CVE-2026-45419 | HIGH | 8.5 | 0.3% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call Template... |
| CVE-2026-45417 | HIGH | 8.7 | 0.2% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status... |
| CVE-2026-45320 | HIGH | 8.7 | 0.3% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such... |
| CVE-2026-40957 | HIGH | 7.5 | 0.3% | Jul 15, 2026 | o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers... |
| CVE-2026-40952 | HIGH | 7.8 | 0.1% | Jul 15, 2026 | CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to... |
| CVE-2026-62351 | HIGH | 7.5 | — | Jul 15, 2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/sr... |
| CVE-2026-62350 | HIGH | 7.2 | 0.4% | Jul 15, 2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user wit... |
| CVE-2026-62349 | HIGH | 8.3 | — | Jul 15, 2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, sourc... |
| CVE-2026-49987 | HIGH | 7.5 | — | Jul 15, 2026 | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitSha... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now