2026 CVE Vulnerabilities
44,807 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48956 | MEDIUM | 5 | 0.3% | Jul 7, 2026 | An improper access check allows users to display a list of modules in the frontend. |
| CVE-2026-48955 | MEDIUM | 6.5 | 0.3% | Jul 7, 2026 | An improper access check allows unauthorized users to access workflow stage and transition information. |
| CVE-2026-48954 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Improper validation leads to a generic XSS vector in the language override feature. |
| CVE-2026-48953 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the generic image output layout. |
| CVE-2026-48952 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. |
| CVE-2026-48951 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. |
| CVE-2026-48950 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. |
| CVE-2026-48949 | MEDIUM | 6.1 | 0.3% | Jul 7, 2026 | Lack of validation leads to an XSS vulnerability in the MFA management views. |
| CVE-2026-48947 | MEDIUM | 4.9 | 0.3% | Jul 7, 2026 | An improper access check allows privileged users to overwrite media files without editing permissions. |
| CVE-2026-14969 | MEDIUM | 4.4 | 0.1% | Jul 7, 2026 | A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vecto... |
| CVE-2026-59709 | MEDIUM | 5.3 | 0.2% | Jul 7, 2026 | Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field wh... |
| CVE-2026-53878 | MEDIUM | 6.1 | 0.2% | Jul 7, 2026 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin... |
| CVE-2026-53877 | MEDIUM | 6.3 | 0.3% | Jul 7, 2026 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read... |
| CVE-2026-48588 | MEDIUM | 5.3 | 0.4% | Jul 7, 2026 | An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`... |
| CVE-2026-14940 | MEDIUM | 5.3 | 0.3% | Jul 7, 2026 | A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) ... |
| CVE-2026-12948 | MEDIUM | 4.8 | 0.3% | Jul 7, 2026 | A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP... |
| CVE-2026-12352 | MEDIUM | 5.9 | 0.3% | Jul 7, 2026 | This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on t... |
| CVE-2026-10659 | MEDIUM | 4.7 | 0.1% | Jul 7, 2026 | The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, ... |
| CVE-2026-49487 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger ... |
| CVE-2026-49296 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the... |
| CVE-2026-48892 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRET... |
| CVE-2026-48891 | MEDIUM | 4.3 | 0.4% | Jul 7, 2026 | A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the t... |
| CVE-2026-48828 | MEDIUM | 6.5 | 0.4% | Jul 7, 2026 | The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `shoul... |
| CVE-2026-14868 | MEDIUM | 5.5 | 0.1% | Jul 7, 2026 | The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of Pc... |
| CVE-2026-14867 | MEDIUM | 5.5 | 0.1% | Jul 7, 2026 | Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now