2026 CVE Vulnerabilities
44,807 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55432 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55431 | MEDIUM | 6.1 | 0.4% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55430 | MEDIUM | 6.8 | 0.2% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55079 | MEDIUM | 6.5 | 0.6% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and pr... |
| CVE-2026-55078 | MEDIUM | 6.5 | 0.6% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and pr... |
| CVE-2026-50811 | MEDIUM | 6.5 | 0.3% | Jul 7, 2026 | An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736... |
| CVE-2026-50810 | MEDIUM | 5.5 | 0.1% | Jul 7, 2026 | A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35... |
| CVE-2026-36163 | MEDIUM | 5.4 | 0.2% | Jul 7, 2026 | An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execut... |
| CVE-2026-36162 | MEDIUM | 5.4 | 0.1% | Jul 7, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 all... |
| CVE-2026-58266 | MEDIUM | 6.5 | 0.2% | Jul 7, 2026 | Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with t... |
| CVE-2026-55490 | MEDIUM | 6.5 | 0.6% | Jul 7, 2026 | OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a()... |
| CVE-2026-54698 | MEDIUM | 6 | 0.2% | Jul 7, 2026 | Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a ... |
| CVE-2026-54601 | MEDIUM | 6.3 | 0.2% | Jul 7, 2026 | FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticat... |
| CVE-2026-50179 | MEDIUM | 4.2 | 0.3% | Jul 7, 2026 | Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/s... |
| CVE-2026-45796 | MEDIUM | 6.5 | 0.3% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13... |
| CVE-2026-58470 | MEDIUM | 6.9 | 0.2% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range(... |
| CVE-2026-55647 | MEDIUM | 5.1 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stor... |
| CVE-2026-55434 | MEDIUM | 6.5 | 0.5% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and pr... |
| CVE-2026-55417 | MEDIUM | 6.9 | 0.2% | Jul 7, 2026 | Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user ena... |
| CVE-2026-53935 | MEDIUM | 6.9 | 0.3% | Jul 7, 2026 | Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 t... |
| CVE-2026-46700 | MEDIUM | 4.3 | 0.3% | Jul 7, 2026 | Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-serve... |
| CVE-2026-46672 | MEDIUM | 4.6 | 0.2% | Jul 7, 2026 | Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in pac... |
| CVE-2026-58468 | MEDIUM | 5.5 | 0.2% | Jul 7, 2026 | NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows au... |
| CVE-2026-44877 | MEDIUM | 6.5 | 0.3% | Jul 7, 2026 | An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960... |
| CVE-2026-55435 | MEDIUM | 5.4 | 0.3% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now