2026 CVE Vulnerabilities
45,110 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34196 | HIGH | 7.8 | 0.1% | Jul 10, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow a... |
| CVE-2026-57850 | HIGH | 8.7 | 0.4% | Jul 10, 2026 | RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a l... |
| CVE-2026-55827 | HIGH | 8.8 | 0.5% | Jul 10, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-... |
| CVE-2026-55789 | HIGH | 8.5 | 0.3% | Jul 10, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML app... |
| CVE-2026-55466 | HIGH | 8.7 | 0.4% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP... |
| CVE-2026-55452 | HIGH | 7.3 | 0.3% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent ... |
| CVE-2026-55377 | HIGH | 8.1 | 0.3% | Jul 10, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-... |
| CVE-2026-11321 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL ... |
| CVE-2026-6212 | HIGH | 8.8 | — | Jul 10, 2026 | Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Pri... |
| CVE-2026-61461 | HIGH | 8.8 | 0.4% | Jul 10, 2026 | Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers ... |
| CVE-2026-61460 | HIGH | 8.8 | — | Jul 10, 2026 | Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController,... |
| CVE-2026-55516 | HIGH | 7.7 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} ch... |
| CVE-2026-55460 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and u... |
| CVE-2026-54329 | HIGH | 7.7 | — | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request ... |
| CVE-2026-53450 | HIGH | 7.4 | 0.3% | Jul 10, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by d... |
| CVE-2026-53448 | HIGH | 7.2 | 0.7% | Jul 10, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passe... |
| CVE-2026-56668 | HIGH | 8.1 | 0.2% | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for ur... |
| CVE-2026-56667 | HIGH | 7.3 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPreconditi... |
| CVE-2026-55672 | HIGH | 7.4 | — | Jul 10, 2026 | ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchan... |
| CVE-2026-59190 | HIGH | 8.7 | — | Jul 10, 2026 | grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.5... |
| CVE-2026-59162 | HIGH | 7.5 | 0.5% | Jul 10, 2026 | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses... |
| CVE-2026-59161 | HIGH | 7.5 | 0.5% | Jul 10, 2026 | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming w... |
| CVE-2026-56675 | HIGH | 8.3 | — | Jul 10, 2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* acce... |
| CVE-2026-55687 | HIGH | 7.5 | — | Jul 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possib... |
| CVE-2026-55641 | HIGH | 8.2 | — | Jul 10, 2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by re... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now