2026 CVE Vulnerabilities
44,088 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59927 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/dir... |
| CVE-2026-59926 | MEDIUM | 6.1 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/direc... |
| CVE-2026-59924 | MEDIUM | 5.9 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes use... |
| CVE-2026-59923 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block p... |
| CVE-2026-59897 | MEDIUM | 5.3 | 0.1% | Jul 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS... |
| CVE-2026-59896 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/j... |
| CVE-2026-59895 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in... |
| CVE-2026-59890 | MEDIUM | 6.1 | 0.3% | Jul 8, 2026 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to ... |
| CVE-2026-59883 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar... |
| CVE-2026-59882 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not ... |
| CVE-2026-59261 | MEDIUM | 6.5 | 0.1% | Jul 8, 2026 | OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provide... |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.4% | Jul 8, 2026 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of... |
| CVE-2026-29007 | MEDIUM | 6.9 | 0.5% | Jul 8, 2026 | U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFI... |
| CVE-2026-59876 | MEDIUM | 4.8 | 0.2% | Jul 8, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text For... |
| CVE-2026-59875 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX ... |
| CVE-2026-57439 | MEDIUM | 5 | 0.1% | Jul 8, 2026 | CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart opera... |
| CVE-2026-55761 | MEDIUM | 5.9 | 0.3% | Jul 8, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t... |
| CVE-2026-54344 | MEDIUM | 4.7 | 0.2% | Jul 8, 2026 | ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview dep... |
| CVE-2026-15063 | MEDIUM | 6.3 | 0.2% | Jul 8, 2026 | A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication... |
| CVE-2026-55873 | MEDIUM | 4.3 | — | Jul 8, 2026 | SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables ar... |
| CVE-2026-55668 | MEDIUM | 6.3 | — | Jul 8, 2026 | File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor ... |
| CVE-2026-15044 | MEDIUM | 6.3 | 0.2% | Jul 8, 2026 | A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific s... |
| CVE-2026-15036 | MEDIUM | 4.3 | 0.4% | Jul 8, 2026 | A vulnerability was determined in Harness up to 2.28.2. This vulnerability affects the function getAuthorizedSpaces of t... |
| CVE-2026-11903 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr... |
| CVE-2026-60125 | MEDIUM | 5.3 | 0.2% | Jul 8, 2026 | MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not en... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now