2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14617 | LOW | 3.1 | 0.2% | Jul 3, 2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function Gatewa... |
| CVE-2026-14615 | LOW | 2.7 | 0.2% | Jul 3, 2026 | A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative service... |
| CVE-2026-46466 | LOW | 2.7 | 0.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-56085 | LOW | 3.3 | 0.1% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-13743 | LOW | 3.3 | 0.1% | Jul 2, 2026 | CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptogr... |
| CVE-2026-54891 | LOW | 3.7 | 0.1% | Jul 2, 2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl... |
| CVE-2026-11781 | LOW | 2.7 | 0.1% | Jul 2, 2026 | The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by... |
| CVE-2026-11578 | LOW | 2.7 | 0.1% | Jul 2, 2026 | The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to th... |
| CVE-2026-54260 | LOW | 2.7 | 0.2% | Jul 1, 2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an aut... |
| CVE-2026-8387 | LOW | 2.4 | 0.4% | Jul 1, 2026 | A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path traversal when extract... |
| CVE-2026-11880 | LOW | 3.1 | 0.1% | Jul 1, 2026 | The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription canc... |
| CVE-2026-44042 | LOW | 3.7 | 0.3% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the Base64 decode helper used for HTTP Basic authentic... |
| CVE-2026-41579 | LOW | 3.3 | 0.2% | Jul 1, 2026 | runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1... |
| CVE-2026-54898 | LOW | 2.1 | 0.1% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2,Oj::Parse... |
| CVE-2026-54897 | LOW | 2.1 | 0.1% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to 3.17.2, Oj::Doc iterators (e... |
| CVE-2026-54896 | LOW | 2.1 | 0.1% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in ... |
| CVE-2026-56364 | LOW | 1.9 | 0.1% | Jun 30, 2026 | ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing ma... |
| CVE-2026-54696 | LOW | 3.7 | 0.3% | Jun 30, 2026 | Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when t... |
| CVE-2026-13982 | LOW | 3.1 | 0.2% | Jun 30, 2026 | Incorrect security UI in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised... |
| CVE-2026-13963 | LOW | 3.1 | 0.1% | Jun 30, 2026 | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced... |
| CVE-2026-13955 | LOW | 3.3 | 0.1% | Jun 30, 2026 | Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a lo... |
| CVE-2026-13948 | LOW | 3.1 | 0.1% | Jun 30, 2026 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced ... |
| CVE-2026-13945 | LOW | 3.1 | 0.1% | Jun 30, 2026 | Insufficient policy enforcement in Extensions in Google Chrome on Linux prior to 150.0.7871.47 allowed an attacker who c... |
| CVE-2026-13944 | LOW | 3.1 | 0.1% | Jun 30, 2026 | Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker wh... |
| CVE-2026-13942 | LOW | 3.3 | 0.1% | Jun 30, 2026 | Inappropriate implementation in Video Capture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a local attack... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now