2026 CVE Vulnerabilities
44,809 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32718 | MEDIUM | 6.5 | 0.2% | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-59711 | MEDIUM | 6.1 | 0.2% | Jul 6, 2026 | showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitr... |
| CVE-2026-55514 | MEDIUM | 6.5 | 0.3% | Jul 6, 2026 | vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a... |
| CVE-2026-54764 | MEDIUM | 5.8 | 0.4% | Jul 6, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middle... |
| CVE-2026-50135 | MEDIUM | 5.5 | 0.4% | Jul 6, 2026 | Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows... |
| CVE-2026-48267 | MEDIUM | 5.5 | 0.1% | Jul 6, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an... |
| CVE-2026-33734 | MEDIUM | 6.9 | 0.2% | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injecti... |
| CVE-2026-21384 | MEDIUM | 5.3 | 0.1% | Jul 6, 2026 | Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported ... |
| CVE-2026-21370 | MEDIUM | 5.3 | 0.1% | Jul 6, 2026 | Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values. |
| CVE-2026-21369 | MEDIUM | 5.3 | 0.1% | Jul 6, 2026 | Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. |
| CVE-2026-21368 | MEDIUM | 5.3 | 0.1% | Jul 6, 2026 | Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks. |
| CVE-2026-59089 | MEDIUM | 5.5 | 0.1% | Jul 6, 2026 | A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calc... |
| CVE-2026-58404 | MEDIUM | 6.8 | 0.2% | Jul 6, 2026 | Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests t... |
| CVE-2026-58403 | MEDIUM | 6.5 | 0.4% | Jul 6, 2026 | Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files und... |
| CVE-2026-58402 | MEDIUM | 5.4 | 0.3% | Jul 6, 2026 | Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-f... |
| CVE-2026-55646 | MEDIUM | 6.5 | 0.3% | Jul 6, 2026 | vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions a... |
| CVE-2026-50134 | MEDIUM | 5.8 | 0.3% | Jul 6, 2026 | Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL i... |
| CVE-2026-50133 | MEDIUM | 6.1 | 0.3% | Jul 6, 2026 | Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to... |
| CVE-2026-44362 | MEDIUM | 5.5 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-14898 | MEDIUM | 6.5 | 0.2% | Jul 6, 2026 | The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could pl... |
| CVE-2026-55798 | MEDIUM | 4.5 | 0.1% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by ... |
| CVE-2026-54291 | MEDIUM | 5.9 | 0.3% | Jul 6, 2026 | pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections ... |
| CVE-2026-12154 | MEDIUM | 6.4 | 0.2% | Jul 6, 2026 | The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2026-40257 | MEDIUM | 5.5 | 0.1% | Jul 6, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-59152 | MEDIUM | 5 | 0.2% | Jul 6, 2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can se... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now