2026 CVE Vulnerabilities
44,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46485 | HIGH | 8.2 | 0.3% | Jul 15, 2026 | Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated user... |
| CVE-2026-15895 | HIGH | 8.4 | — | Jul 15, 2026 | OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent ... |
| CVE-2026-12997 | HIGH | 7.5 | — | Jul 15, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4... |
| CVE-2026-59258 | HIGH | 8.3 | — | Jul 15, 2026 | immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that all... |
| CVE-2026-59255 | HIGH | 7.1 | — | Jul 15, 2026 | BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes AP... |
| CVE-2026-58660 | HIGH | 8.1 | — | Jul 15, 2026 | Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-d... |
| CVE-2026-58659 | HIGH | 8.4 | 0.2% | Jul 15, 2026 | PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_st... |
| CVE-2026-58658 | HIGH | 8.8 | — | Jul 15, 2026 | GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that a... |
| CVE-2026-56687 | HIGH | 7.8 | — | Jul 15, 2026 | Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attack... |
| CVE-2026-53518 | HIGH | 8.1 | 0.5% | Jul 15, 2026 | Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oau... |
| CVE-2026-53517 | HIGH | 8.1 | 0.4% | Jul 15, 2026 | Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-a... |
| CVE-2026-53516 | HIGH | 8.3 | 0.2% | Jul 15, 2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback... |
| CVE-2026-53515 | HIGH | 7.1 | 0.2% | Jul 15, 2026 | Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/ss... |
| CVE-2026-53514 | HIGH | 7.7 | 0.2% | Jul 15, 2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when... |
| CVE-2026-45337 | HIGH | 7.6 | 0.1% | Jul 15, 2026 | Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorizat... |
| CVE-2026-40501 | HIGH | 8.8 | — | Jul 15, 2026 | Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerability in S... |
| CVE-2026-20297 | HIGH | 7.2 | 0.5% | Jul 15, 2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below... |
| CVE-2026-20296 | HIGH | 8.3 | 0.2% | Jul 15, 2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.26... |
| CVE-2026-12382 | HIGH | 8.2 | 0.4% | Jul 15, 2026 | A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove t... |
| CVE-2026-10673 | HIGH | 8.3 | — | Jul 15, 2026 | The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ether... |
| CVE-2026-59955 | HIGH | 7.5 | — | Jul 15, 2026 | Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior... |
| CVE-2026-59954 | HIGH | 7.5 | — | Jul 15, 2026 | Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior... |
| CVE-2026-48799 | HIGH | 7.7 | — | Jul 15, 2026 | Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authentic... |
| CVE-2026-45804 | HIGH | 7.5 | 0.3% | Jul 15, 2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretraine... |
| CVE-2026-45793 | HIGH | 7.5 | — | Jul 15, 2026 | Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConf... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now