2026 CVE Vulnerabilities
44,088 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54777 | MEDIUM | 6.5 | 0.1% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-48492 | MEDIUM | 6.5 | 0.4% | Jul 8, 2026 | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpo... |
| CVE-2026-39179 | MEDIUM | 6.3 | 0.1% | Jul 8, 2026 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t... |
| CVE-2026-39178 | MEDIUM | 6.3 | 0.1% | Jul 8, 2026 | A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t... |
| CVE-2026-8472 | MEDIUM | 4.3 | 0.2% | Jul 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.... |
| CVE-2026-7492 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 1... |
| CVE-2026-6896 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19... |
| CVE-2026-58494 | MEDIUM | 6.5 | 0.1% | Jul 8, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation a... |
| CVE-2026-58211 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58207 | MEDIUM | 6.5 | 0.5% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58191 | MEDIUM | 6.1 | 0.3% | Jul 8, 2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior... |
| CVE-2026-55542 | MEDIUM | 4.3 | 0.4% | Jul 8, 2026 | Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks a... |
| CVE-2026-54590 | MEDIUM | 5.9 | 0.3% | Jul 8, 2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to... |
| CVE-2026-35211 | MEDIUM | 6.5 | 0.4% | Jul 8, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0... |
| CVE-2026-15174 | MEDIUM | 5.5 | 0.1% | Jul 8, 2026 | Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service |
| CVE-2026-15173 | MEDIUM | 5.5 | 0.1% | Jul 8, 2026 | pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service |
| CVE-2026-15172 | MEDIUM | 5.5 | 0.1% | Jul 8, 2026 | FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service |
| CVE-2026-15171 | MEDIUM | 5.5 | 0.1% | Jul 8, 2026 | SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service |
| CVE-2026-15170 | MEDIUM | 5.5 | 0.1% | Jul 8, 2026 | Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service |
| CVE-2026-15167 | MEDIUM | 5.5 | 0.3% | Jul 8, 2026 | DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service |
| CVE-2026-15166 | MEDIUM | 5.5 | 0.1% | Jul 8, 2026 | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service |
| CVE-2026-15165 | MEDIUM | 5.5 | 0.2% | Jul 8, 2026 | TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service |
| CVE-2026-15164 | MEDIUM | 5.5 | 0.2% | Jul 8, 2026 | Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service |
| CVE-2026-14896 | MEDIUM | 4.2 | 0.2% | Jul 8, 2026 | HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volume... |
| CVE-2026-13320 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now