2026 CVE Vulnerabilities
45,141 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15685 | HIGH | 7.5 | 0.4% | Jul 13, 2026 | Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote... |
| CVE-2026-15684 | HIGH | 7.3 | 0.1% | Jul 13, 2026 | Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attac... |
| CVE-2026-15683 | HIGH | 7.5 | 0.1% | Jul 13, 2026 | Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulne... |
| CVE-2026-15680 | HIGH | 7.5 | 0.3% | Jul 13, 2026 | Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerabil... |
| CVE-2026-15597 | HIGH | 7.3 | 0.3% | Jul 13, 2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. This affects an unkno... |
| CVE-2026-58410 | HIGH | 7.1 | 0.2% | Jul 13, 2026 | ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the fam... |
| CVE-2026-48364 | HIGH | 8.2 | 0.2% | Jul 13, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that c... |
| CVE-2026-48363 | HIGH | 8.2 | 0.2% | Jul 13, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that c... |
| CVE-2026-55773 | HIGH | 8.8 | 0.3% | Jul 13, 2026 | CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi... |
| CVE-2026-55771 | HIGH | 8.8 | 0.3% | Jul 13, 2026 | CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi... |
| CVE-2026-55772 | HIGH | 8.8 | 0.5% | Jul 13, 2026 | CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi... |
| CVE-2026-49972 | HIGH | 8.8 | 0.8% | Jul 13, 2026 | Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remo... |
| CVE-2026-49970 | HIGH | 8.8 | 0.8% | Jul 13, 2026 | Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows a... |
| CVE-2026-49969 | HIGH | 7.4 | 0.2% | Jul 13, 2026 | Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue... |
| CVE-2026-26396 | HIGH | 7.5 | — | Jul 13, 2026 | OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/applicati... |
| CVE-2026-61463 | HIGH | 8.8 | — | Jul 13, 2026 | Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to m... |
| CVE-2026-57432 | HIGH | 8.4 | 0.2% | Jul 13, 2026 | Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack... |
| CVE-2026-59245 | HIGH | 8.1 | 0.4% | Jul 13, 2026 | In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission reso... |
| CVE-2026-58065 | HIGH | 8.1 | 0.5% | Jul 13, 2026 | The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling S... |
| CVE-2026-40553 | HIGH | 7.5 | — | Jul 13, 2026 | Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue... |
| CVE-2026-40467 | HIGH | 7.5 | — | Jul 13, 2026 | Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may ... |
| CVE-2026-15584 | HIGH | 7.5 | 0.2% | Jul 13, 2026 | A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged d... |
| CVE-2026-61956 | HIGH | 7.1 | 0.2% | Jul 13, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allo... |
| CVE-2026-61955 | HIGH | 7.6 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم ... |
| CVE-2026-59521 | HIGH | 7.2 | 0.5% | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Inj... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now