2026 CVE Vulnerabilities
44,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56149 | MEDIUM | 4.9 | 0.3% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce... |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). ... |
| CVE-2026-49088 | MEDIUM | 4.4 | 0.2% | Jul 1, 2026 | Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the option... |
| CVE-2026-49087 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A... |
| CVE-2026-34098 | MEDIUM | 4.8 | 0.1% | Jul 1, 2026 | Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action att... |
| CVE-2026-34097 | MEDIUM | 4.8 | 0.1% | Jul 1, 2026 | Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attri... |
| CVE-2026-34096 | MEDIUM | 4.8 | 0.1% | Jul 1, 2026 | Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribut... |
| CVE-2026-27409 | MEDIUM | 5.3 | — | Jul 1, 2026 | Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2026-13211 | MEDIUM | 4.3 | 0.1% | Jul 1, 2026 | The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption ke... |
| CVE-2026-12480 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE... |
| CVE-2026-8480 | MEDIUM | 4.3 | — | Jul 1, 2026 | A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) ,... |
| CVE-2026-58038 | MEDIUM | 6.1 | 0.2% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58037 | MEDIUM | 6.1 | 0.4% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58033 | MEDIUM | 6.5 | 0.4% | Jul 1, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne... |
| CVE-2026-58032 | MEDIUM | 6.1 | 0.4% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58030 | MEDIUM | 6.1 | 0.4% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58029 | MEDIUM | 6.5 | 0.5% | Jul 1, 2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiC... |
| CVE-2026-58028 | MEDIUM | 5.4 | 0.4% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58027 | MEDIUM | 6.5 | 0.4% | Jul 1, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vul... |
| CVE-2026-58026 | MEDIUM | 5.7 | 0.4% | Jul 1, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne... |
| CVE-2026-58024 | MEDIUM | 5.7 | 0.4% | Jul 1, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne... |
| CVE-2026-6686 | MEDIUM | 4.6 | 0.2% | Jul 1, 2026 | FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-... |
| CVE-2026-6684 | MEDIUM | 4.6 | 0.2% | Jul 1, 2026 | FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived f... |
| CVE-2026-6683 | MEDIUM | 4.6 | 0.2% | Jul 1, 2026 | FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to b... |
| CVE-2026-6283 | MEDIUM | 5.4 | — | Jul 1, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now