2026 CVE Vulnerabilities
44,965 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59097 | MEDIUM | 6.9 | 0.3% | Jul 2, 2026 | Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to creat... |
| CVE-2026-58580 | MEDIUM | 6 | 0.2% | Jul 2, 2026 | LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. ... |
| CVE-2026-58579 | MEDIUM | 5.4 | 0.2% | Jul 2, 2026 | RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalize... |
| CVE-2026-58381 | MEDIUM | 6.1 | 0.1% | Jul 2, 2026 | A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe... |
| CVE-2026-55950 | MEDIUM | 5.9 | 0.4% | Jul 2, 2026 | Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an u... |
| CVE-2026-54887 | MEDIUM | 4.8 | 0.2% | Jul 2, 2026 | Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computatio... |
| CVE-2026-54886 | MEDIUM | 4.3 | 0.3% | Jul 2, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an auth... |
| CVE-2026-53422 | MEDIUM | 4.3 | 0.3% | Jul 2, 2026 | Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to ... |
| CVE-2026-50282 | MEDIUM | 4.9 | — | Jul 2, 2026 | Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and... |
| CVE-2026-55110 | MEDIUM | 6.1 | 0.2% | Jul 2, 2026 | A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (COR... |
| CVE-2026-12166 | MEDIUM | 5.5 | — | Jul 2, 2026 | A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to c... |
| CVE-2026-58653 | MEDIUM | 5.3 | — | Jul 2, 2026 | PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL wo... |
| CVE-2026-4772 | MEDIUM | 5.4 | — | Jul 2, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defens... |
| CVE-2026-4770 | MEDIUM | 4.6 | — | Jul 2, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defens... |
| CVE-2026-57764 | MEDIUM | 6.5 | — | Jul 2, 2026 | Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions. |
| CVE-2026-57763 | MEDIUM | 6.5 | — | Jul 2, 2026 | Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions. |
| CVE-2026-57762 | MEDIUM | 5.9 | — | Jul 2, 2026 | Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions. |
| CVE-2026-57760 | MEDIUM | 5.3 | — | Jul 2, 2026 | Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-57755 | MEDIUM | 6.5 | — | Jul 2, 2026 | Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions. |
| CVE-2026-57754 | MEDIUM | 6.5 | — | Jul 2, 2026 | Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions. |
| CVE-2026-57753 | MEDIUM | 5.3 | — | Jul 2, 2026 | Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions. |
| CVE-2026-57750 | MEDIUM | 5.3 | — | Jul 2, 2026 | Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions. |
| CVE-2026-57747 | MEDIUM | 6.5 | — | Jul 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions. |
| CVE-2026-57731 | MEDIUM | 6.5 | — | Jul 2, 2026 | Contributor Broken Access Control in Flatsome <= 3.20.5 versions. |
| CVE-2026-57730 | MEDIUM | 4.3 | — | Jul 2, 2026 | Subscriber Broken Access Control in Flatsome <= 3.20.5 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now