2026 CVE Vulnerabilities
44,078 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11869 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-proces... |
| CVE-2026-15138 | MEDIUM | 6.3 | 0.3% | Jul 9, 2026 | A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validat... |
| CVE-2026-47646 | MEDIUM | 6.1 | 0.5% | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allo... |
| CVE-2026-54779 | MEDIUM | 5.9 | 0.3% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-54778 | MEDIUM | 6.2 | 0.1% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-54776 | MEDIUM | 4.4 | 0.1% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-54775 | MEDIUM | 6.5 | 0.3% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-54773 | MEDIUM | 5.9 | 0.2% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-15131 | MEDIUM | 4.3 | 0.2% | Jul 8, 2026 | Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass ... |
| CVE-2026-15130 | MEDIUM | 4.3 | 0.2% | Jul 8, 2026 | Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypa... |
| CVE-2026-15128 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbit... |
| CVE-2026-15127 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbit... |
| CVE-2026-15124 | MEDIUM | 4.3 | 0.2% | Jul 8, 2026 | Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypas... |
| CVE-2026-15109 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sens... |
| CVE-2026-15108 | MEDIUM | 4.3 | 0.1% | Jul 8, 2026 | Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to ... |
| CVE-2026-15105 | MEDIUM | 6.3 | 0.3% | Jul 8, 2026 | A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the... |
| CVE-2026-5923 | MEDIUM | 6 | 0.1% | Jul 8, 2026 | Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage. |
| CVE-2026-5922 | MEDIUM | 5.9 | 0.2% | Jul 8, 2026 | The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpa... |
| CVE-2026-55877 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() T... |
| CVE-2026-54777 | MEDIUM | 6.5 | 0.1% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-48492 | MEDIUM | 6.5 | 0.4% | Jul 8, 2026 | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpo... |
| CVE-2026-39179 | MEDIUM | 6.3 | 0.1% | Jul 8, 2026 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t... |
| CVE-2026-39178 | MEDIUM | 6.3 | 0.1% | Jul 8, 2026 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t... |
| CVE-2026-8472 | MEDIUM | 4.3 | 0.2% | Jul 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.... |
| CVE-2026-7492 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now