2026 CVE Vulnerabilities
44,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49858 | MEDIUM | 5.9 | 0.2% | Jul 1, 2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29,... |
| CVE-2026-58517 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension ... |
| CVE-2026-55628 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.... |
| CVE-2026-55597 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26... |
| CVE-2026-55595 | MEDIUM | 4.7 | 0.1% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-55594 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-55577 | MEDIUM | 5.9 | 0.2% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-55510 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-53489 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plu... |
| CVE-2026-53467 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-53466 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-47262 | MEDIUM | 5.5 | 0.5% | Jul 1, 2026 | containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vuln... |
| CVE-2026-38142 | MEDIUM | 6.5 | 0.7% | Jul 1, 2026 | An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.0... |
| CVE-2026-14358 | MEDIUM | 6.1 | 0.3% | Jul 1, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-13769 | MEDIUM | 6.8 | — | Jul 1, 2026 | Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask ... |
| CVE-2026-5051 | MEDIUM | 4.4 | 0.3% | Jul 1, 2026 | HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin dire... |
| CVE-2026-58520 | MEDIUM | 6.1 | 0.3% | Jul 1, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener E... |
| CVE-2026-57737 | MEDIUM | 6.5 | — | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortco... |
| CVE-2026-57722 | MEDIUM | 5.9 | 0.1% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable ... |
| CVE-2026-51946 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary... |
| CVE-2026-49090 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (C... |
| CVE-2026-57721 | MEDIUM | 5.3 | — | Jul 1, 2026 | Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-57720 | MEDIUM | 4.3 | — | Jul 1, 2026 | Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-56152 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functi... |
| CVE-2026-56151 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now