2026 CVE Vulnerabilities
44,088 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11827 | MEDIUM | 4.9 | 0.3% | Jul 8, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1... |
| CVE-2026-59947 | MEDIUM | 4.7 | 0.1% | Jul 8, 2026 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug ... |
| CVE-2026-59946 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containi... |
| CVE-2026-59820 | MEDIUM | 6.5 | 0.3% | Jul 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Sk... |
| CVE-2026-59819 | MEDIUM | 4.9 | 0.3% | Jul 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's... |
| CVE-2026-58501 | MEDIUM | 5.9 | 0.3% | Jul 8, 2026 | Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing... |
| CVE-2026-58254 | MEDIUM | 6.5 | 0.4% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58252 | MEDIUM | 6.5 | 0.5% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.... |
| CVE-2026-58251 | MEDIUM | 6.5 | 0.5% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.... |
| CVE-2026-58214 | MEDIUM | 4.3 | 0.4% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58209 | MEDIUM | 4.3 | 0.3% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-53624 | MEDIUM | 4.8 | 0.2% | Jul 8, 2026 | Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/hel... |
| CVE-2026-45045 | MEDIUM | 5.3 | 0.5% | Jul 8, 2026 | Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper i... |
| CVE-2026-44512 | MEDIUM | 5.5 | 0.2% | Jul 8, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0,... |
| CVE-2026-44332 | MEDIUM | 5.3 | 0.5% | Jul 8, 2026 | Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAu... |
| CVE-2026-36028 | MEDIUM | 6.8 | 0.2% | Jul 8, 2026 | A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass... |
| CVE-2026-36027 | MEDIUM | 6.8 | 0.3% | Jul 8, 2026 | An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via... |
| CVE-2026-15154 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Ex... |
| CVE-2026-14361 | MEDIUM | 4.7 | 0.1% | Jul 8, 2026 | The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template ... |
| CVE-2026-59938 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared imag... |
| CVE-2026-50813 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the S... |
| CVE-2026-50812 | MEDIUM | 5.5 | 0.1% | Jul 8, 2026 | A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807... |
| CVE-2026-14362 | MEDIUM | 4.9 | 0.3% | Jul 8, 2026 | HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling tha... |
| CVE-2026-59930 | MEDIUM | 4.3 | 0.1% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents direc... |
| CVE-2026-59929 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/rende... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now