2026 CVE Vulnerabilities
44,958 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55945 | MEDIUM | 4.2 | 0.1% | Jul 3, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-... |
| CVE-2026-45489 | MEDIUM | 6.5 | 0.5% | Jul 3, 2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-45488 | MEDIUM | 5.9 | 0.3% | Jul 3, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-28705 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release as... |
| CVE-2026-27783 | MEDIUM | 4.3 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints. |
| CVE-2026-27761 | MEDIUM | 4.3 | 0.4% | Jul 3, 2026 | Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope ... |
| CVE-2026-25782 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the requ... |
| CVE-2026-25779 | MEDIUM | 6.1 | 0.2% | Jul 3, 2026 | Gitea versions up to and including 1.25.4 allow redirect bypasses through raw or percent-encoded backslashes in redirect... |
| CVE-2026-25714 | MEDIUM | 4.3 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization... |
| CVE-2026-20909 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. |
| CVE-2026-14611 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of ... |
| CVE-2026-14610 | MEDIUM | 5.3 | 0.1% | Jul 3, 2026 | A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::Int... |
| CVE-2026-14609 | MEDIUM | 5.6 | 0.3% | Jul 3, 2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue... |
| CVE-2026-14355 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo... |
| CVE-2026-14608 | MEDIUM | 4.3 | 0.2% | Jul 3, 2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1... |
| CVE-2026-14607 | MEDIUM | 5.5 | 0.1% | Jul 3, 2026 | A weakness has been identified in RT-Thread up to 5.0.2. This affects the function sys_getaddrinfo of the file component... |
| CVE-2026-14604 | MEDIUM | 6.3 | 0.2% | Jul 3, 2026 | A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporte... |
| CVE-2026-14631 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends eit... |
| CVE-2026-14620 | MEDIUM | 4.7 | 0.1% | Jul 3, 2026 | webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a... |
| CVE-2026-14614 | MEDIUM | 5.4 | 0.2% | Jul 3, 2026 | A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP)... |
| CVE-2026-14613 | MEDIUM | 4.9 | 0.2% | Jul 3, 2026 | A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see informat... |
| CVE-2026-14612 | MEDIUM | 4.2 | 0.1% | Jul 3, 2026 | Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memor... |
| CVE-2026-49813 | MEDIUM | 6.7 | 0.5% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-46465 | MEDIUM | 5.5 | 0.2% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-46464 | MEDIUM | 4.9 | 0.4% | Jul 3, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now