2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13939 | LOW | 3.1 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 150.0.7871.47 allowed a remo... |
| CVE-2026-58371 | LOW | 3.1 | 0.2% | Jun 30, 2026 | SeaweedFS before 4.30 reflects the callback query parameter verbatim into responses served with Content-Type application... |
| CVE-2026-10654 | LOW | 3.1 | 0.1% | Jun 30, 2026 | A race condition in the Zephyr Bluetooth Classic RFCOMM host stack (subsys/bluetooth/host/classic/rfcomm.c) mishandles a... |
| CVE-2026-13758 | LOW | 3.7 | 0.2% | Jun 29, 2026 | CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt... |
| CVE-2026-53427 | LOW | 2.3 | — | Jun 29, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx all... |
| CVE-2026-13587 | LOW | 3.7 | — | Jun 29, 2026 | A vulnerability was found in seladb PcapPlusPlus 25.05. The affected element is the function parse_by_block_type of the ... |
| CVE-2026-13574 | LOW | 3.3 | 0.1% | Jun 29, 2026 | A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr i... |
| CVE-2026-13573 | LOW | 3.3 | 0.1% | Jun 29, 2026 | A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the li... |
| CVE-2026-13570 | LOW | 3.5 | — | Jun 29, 2026 | A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the f... |
| CVE-2026-13558 | LOW | 3.5 | — | Jun 29, 2026 | A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown proces... |
| CVE-2026-13523 | LOW | 3.3 | 0.1% | Jun 29, 2026 | A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c... |
| CVE-2026-13514 | LOW | 2.4 | 0.1% | Jun 29, 2026 | A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown proc... |
| CVE-2026-13511 | LOW | 3.1 | 0.2% | Jun 28, 2026 | A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversa... |
| CVE-2026-13510 | LOW | 3.7 | 0.2% | Jun 28, 2026 | A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in... |
| CVE-2026-13504 | LOW | 3.5 | 0.2% | Jun 28, 2026 | A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code o... |
| CVE-2026-13493 | LOW | 3.1 | 0.2% | Jun 28, 2026 | A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file ba... |
| CVE-2026-13491 | LOW | 3.7 | 0.4% | Jun 28, 2026 | A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetIn... |
| CVE-2026-13489 | LOW | 3.1 | 0.2% | Jun 28, 2026 | A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of t... |
| CVE-2026-13483 | LOW | 3.1 | 0.1% | Jun 28, 2026 | A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the fil... |
| CVE-2026-13482 | LOW | 3.7 | 0.2% | Jun 28, 2026 | A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file... |
| CVE-2026-10644 | LOW | 3.1 | 0.1% | Jun 28, 2026 | The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains ... |
| CVE-2026-47206 | LOW | 2.3 | — | Jun 26, 2026 | Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Proto... |
| CVE-2026-3472 | LOW | 3.5 | 0.2% | Jun 26, 2026 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image render... |
| CVE-2026-57940 | LOW | 2.1 | — | Jun 26, 2026 | HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The functi... |
| CVE-2026-48936 | LOW | 3.3 | 0.1% | Jun 26, 2026 | A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now