2026 CVE Vulnerabilities
44,992 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20462 | MEDIUM | 6.7 | 0.1% | Jul 1, 2026 | In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation o... |
| CVE-2026-20461 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of ser... |
| CVE-2026-20460 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote informa... |
| CVE-2026-20459 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2026-20457 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2026-57963 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, an... |
| CVE-2026-57962 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitr... |
| CVE-2026-54903 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load ... |
| CVE-2026-54902 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, is vulnerabl... |
| CVE-2026-54901 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Pars... |
| CVE-2026-54900 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in ... |
| CVE-2026-54899 | MEDIUM | 6.3 | 0.4% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, disabling sy... |
| CVE-2026-54502 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump ... |
| CVE-2026-54500 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load ... |
| CVE-2026-56777 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Pytho... |
| CVE-2026-56399 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpo... |
| CVE-2026-56377 | MEDIUM | 4.8 | 0.2% | Jun 30, 2026 | ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallo... |
| CVE-2026-56369 | MEDIUM | 6.3 | 0.2% | Jun 30, 2026 | ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to A... |
| CVE-2026-56365 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers c... |
| CVE-2026-56363 | MEDIUM | 4.8 | 0.1% | Jun 30, 2026 | ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attacker... |
| CVE-2026-56356 | MEDIUM | 5.4 | 0.2% | Jun 30, 2026 | n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfigu... |
| CVE-2026-56334 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and ano... |
| CVE-2026-56333 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allo... |
| CVE-2026-56331 | MEDIUM | 6.9 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 ... |
| CVE-2026-56327 | MEDIUM | 6.9 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function tha... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now