2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13529 | MEDIUM | 5.6 | 0.2% | Jun 29, 2026 | A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/in... |
| CVE-2026-13525 | MEDIUM | 6.3 | 0.2% | Jun 29, 2026 | A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselect... |
| CVE-2026-13524 | MEDIUM | 5.6 | 0.3% | Jun 29, 2026 | A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown cod... |
| CVE-2026-13522 | MEDIUM | 4.3 | 0.3% | Jun 29, 2026 | A security flaw has been discovered in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function S... |
| CVE-2026-13520 | MEDIUM | 6.3 | 0.2% | Jun 29, 2026 | A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the fi... |
| CVE-2026-13513 | MEDIUM | 5 | 0.1% | Jun 29, 2026 | A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0. This vulnerability affects the function SegmentId:... |
| CVE-2026-13512 | MEDIUM | 6.3 | 0.2% | Jun 28, 2026 | A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_... |
| CVE-2026-13509 | MEDIUM | 6.3 | 0.3% | Jun 28, 2026 | A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remov... |
| CVE-2026-13508 | MEDIUM | 5.5 | 0.2% | Jun 28, 2026 | A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers... |
| CVE-2026-13507 | MEDIUM | 5 | 0.1% | Jun 28, 2026 | A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file ... |
| CVE-2026-13503 | MEDIUM | 5.5 | 0.5% | Jun 28, 2026 | A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile o... |
| CVE-2026-13502 | MEDIUM | 4.5 | 0.1% | Jun 28, 2026 | A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file a... |
| CVE-2026-13501 | MEDIUM | 5.3 | 0.7% | Jun 28, 2026 | A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function ... |
| CVE-2026-13499 | MEDIUM | 4.3 | 0.3% | Jun 28, 2026 | A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function o... |
| CVE-2026-13497 | MEDIUM | 6.3 | 0.2% | Jun 28, 2026 | A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi... |
| CVE-2026-13496 | MEDIUM | 6.3 | 0.2% | Jun 28, 2026 | A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of... |
| CVE-2026-13495 | MEDIUM | 4.7 | 0.2% | Jun 28, 2026 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the fi... |
| CVE-2026-13490 | MEDIUM | 6.3 | 0.3% | Jun 28, 2026 | A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document... |
| CVE-2026-10593 | MEDIUM | 6.5 | 0.2% | Jun 28, 2026 | The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications.... |
| CVE-2026-58058 | MEDIUM | 6.9 | 0.3% | Jun 28, 2026 | Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (li... |
| CVE-2026-58057 | MEDIUM | 5 | 0.2% | Jun 28, 2026 | Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparis... |
| CVE-2026-58055 | MEDIUM | 6.3 | 0.2% | Jun 28, 2026 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header an... |
| CVE-2026-58052 | MEDIUM | 4.8 | 0.1% | Jun 28, 2026 | 7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because it... |
| CVE-2026-45259 | MEDIUM | 6.5 | 0.1% | Jun 27, 2026 | sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation... |
| CVE-2026-9242 | MEDIUM | 5.3 | 0.2% | Jun 27, 2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now