2026 CVE Vulnerabilities
45,103 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56238 | HIGH | 8.7 | 0.4% | Jul 12, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint t... |
| CVE-2026-15498 | HIGH | 7.3 | 0.3% | Jul 12, 2026 | A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. This impact... |
| CVE-2026-15497 | HIGH | 7.3 | 0.4% | Jul 12, 2026 | A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file so... |
| CVE-2026-15491 | HIGH | 7.3 | 0.6% | Jul 12, 2026 | A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects ... |
| CVE-2026-15490 | HIGH | 7.3 | 0.4% | Jul 12, 2026 | A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected... |
| CVE-2026-15489 | HIGH | 7.3 | 0.3% | Jul 12, 2026 | A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by t... |
| CVE-2026-15488 | HIGH | 7.3 | 0.3% | Jul 12, 2026 | A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of t... |
| CVE-2026-15484 | HIGH | 8.8 | 0.5% | Jul 12, 2026 | A vulnerability was detected in TRENDnet TEW-821DAP 1.12B01. The affected element is the function sub_41EC14 of the file... |
| CVE-2026-15483 | HIGH | 8.8 | 0.5% | Jul 12, 2026 | A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function sub_41EC14 of the fi... |
| CVE-2026-15482 | HIGH | 7.3 | 0.3% | Jul 12, 2026 | A weakness has been identified in Aster Telecom Azcall 10/11. This issue affects some unknown processing of the file /az... |
| CVE-2026-15481 | HIGH | 8.8 | 1.5% | Jul 12, 2026 | A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_t... |
| CVE-2026-15480 | HIGH | 8.8 | 0.5% | Jul 12, 2026 | A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of the file /... |
| CVE-2026-15479 | HIGH | 7.3 | 0.3% | Jul 12, 2026 | A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file... |
| CVE-2026-58281 | HIGH | 8.3 | 0.7% | Jul 11, 2026 | Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ove... |
| CVE-2026-61870 | HIGH | 7.5 | 0.1% | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attac... |
| CVE-2026-61861 | HIGH | 7.5 | 0.3% | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory alloca... |
| CVE-2026-61857 | HIGH | 7.5 | 0.2% | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP p... |
| CVE-2026-61454 | HIGH | 8.7 | 0.2% | Jul 11, 2026 | The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFI... |
| CVE-2026-61442 | HIGH | 7.1 | 0.3% | Jul 11, 2026 | PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for ... |
| CVE-2026-61439 | HIGH | 8.7 | 0.3% | Jul 11, 2026 | PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults ... |
| CVE-2026-61429 | HIGH | 8.5 | 0.2% | Jul 11, 2026 | PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend th... |
| CVE-2026-61428 | HIGH | 7.3 | 0.2% | Jul 11, 2026 | PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attacke... |
| CVE-2026-61426 | HIGH | 8.8 | 0.3% | Jul 11, 2026 | PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requireme... |
| CVE-2026-56303 | HIGH | 8.7 | 0.3% | Jul 11, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function m... |
| CVE-2026-57828 | HIGH | 8.8 | 0.3% | Jul 11, 2026 | Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downlo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now