2026 CVE Vulnerabilities
44,807 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13199 | MEDIUM | 5.1 | 0.1% | Jul 7, 2026 | EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resul... |
| CVE-2026-8309 | MEDIUM | 5.4 | 0.1% | Jul 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information... |
| CVE-2026-8306 | MEDIUM | 6.1 | 0.1% | Jul 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information... |
| CVE-2026-7380 | MEDIUM | 6.1 | 0.1% | Jul 7, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno... |
| CVE-2026-58315 | MEDIUM | 5.1 | 0.1% | Jul 7, 2026 | Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged... |
| CVE-2026-57870 | MEDIUM | 5.3 | 0.2% | Jul 7, 2026 | Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document template... |
| CVE-2026-10834 | MEDIUM | 4.6 | 0.1% | Jul 7, 2026 | The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile ima... |
| CVE-2026-26053 | MEDIUM | 5.3 | 0.2% | Jul 7, 2026 | An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator ... |
| CVE-2026-42147 | MEDIUM | 4.9 | 0.3% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34198 | MEDIUM | 5.3 | 0.1% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34170 | MEDIUM | 4.3 | 0.2% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-11328 | MEDIUM | 6.4 | 0.2% | Jul 7, 2026 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title ... |
| CVE-2026-53648 | MEDIUM | 5.1 | 0.3% | Jul 7, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product fi... |
| CVE-2026-53647 | MEDIUM | 6.9 | 0.4% | Jul 7, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `ser... |
| CVE-2026-13356 | MEDIUM | 6.3 | 0.1% | Jul 7, 2026 | A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the brows... |
| CVE-2026-53642 | MEDIUM | 5.3 | 0.2% | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Requ... |
| CVE-2026-53641 | MEDIUM | 4.8 | 0.3% | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a stored cros... |
| CVE-2026-59710 | MEDIUM | 6.1 | 0.2% | Jul 6, 2026 | showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/ta... |
| CVE-2026-43927 | MEDIUM | 6.9 | — | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the... |
| CVE-2026-43925 | MEDIUM | 6.9 | 0.3% | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass... |
| CVE-2026-41899 | MEDIUM | 6.5 | 0.3% | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-38979 | MEDIUM | 5.4 | 0.1% | Jul 6, 2026 | ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/... |
| CVE-2026-38973 | MEDIUM | 4.4 | 0.2% | Jul 6, 2026 | mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find... |
| CVE-2026-34167 | MEDIUM | 5 | 0.2% | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34050 | MEDIUM | 6.5 | 0.2% | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now