2026 CVE Vulnerabilities
45,110 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52747 | HIGH | 8.6 | 0.5% | Jul 10, 2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to ... |
| CVE-2026-49394 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_pag... |
| CVE-2026-49213 | HIGH | 8.1 | 0.3% | Jul 10, 2026 | TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHtt... |
| CVE-2026-44795 | HIGH | 8.8 | 1.0% | Jul 10, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3... |
| CVE-2026-41482 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion wer... |
| CVE-2026-15081 | HIGH | 7.4 | 0.3% | Jul 10, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Se... |
| CVE-2026-13244 | HIGH | 8.1 | 0.2% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Ma... |
| CVE-2026-7639 | HIGH | 7.8 | 0.1% | Jul 10, 2026 | Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use afte... |
| CVE-2026-58499 | HIGH | 8.2 | 0.4% | Jul 10, 2026 | EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory... |
| CVE-2026-57574 | HIGH | 7.4 | 0.3% | Jul 10, 2026 | Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-... |
| CVE-2026-57220 | HIGH | 7.5 | 0.4% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configur... |
| CVE-2026-57219 | HIGH | 7.5 | 0.8% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth en... |
| CVE-2026-57215 | HIGH | 8.8 | 0.2% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindi... |
| CVE-2026-57212 | HIGH | 7.7 | 0.3% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP ... |
| CVE-2026-55881 | HIGH | 7.1 | 0.2% | Jul 10, 2026 | OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3... |
| CVE-2026-55880 | HIGH | 7.1 | 0.2% | Jul 10, 2026 | OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran... |
| CVE-2026-55665 | HIGH | 8.5 | 0.3% | Jul 10, 2026 | Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, Grist contained two cross-site scri... |
| CVE-2026-55659 | HIGH | 7.7 | 0.3% | Jul 10, 2026 | Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages... |
| CVE-2026-55405 | HIGH | 7.6 | 0.3% | Jul 10, 2026 | LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.1... |
| CVE-2026-55233 | HIGH | 7.5 | 0.3% | Jul 10, 2026 | OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exi... |
| CVE-2026-55229 | HIGH | 7.5 | 0.4% | Jul 10, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpo... |
| CVE-2026-55213 | HIGH | 7.5 | 0.3% | Jul 10, 2026 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f... |
| CVE-2026-45203 | HIGH | 7.8 | 0.1% | Jul 10, 2026 | Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor... |
| CVE-2026-45196 | HIGH | 7.8 | 0.1% | Jul 10, 2026 | Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU r... |
| CVE-2026-41154 | HIGH | 7.8 | 0.1% | Jul 10, 2026 | Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now