2026 CVE Vulnerabilities
45,376 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59221 | HIGH | 7.7 | — | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitiz... |
| CVE-2026-58378 | HIGH | 8.8 | 0.2% | Jul 9, 2026 | Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB a... |
| CVE-2026-55420 | HIGH | 8.1 | 0.3% | Jul 9, 2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-... |
| CVE-2026-59224 | HIGH | 8 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webu... |
| CVE-2026-59219 | HIGH | 7.1 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redi... |
| CVE-2026-53987 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban ba... |
| CVE-2026-51606 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device t... |
| CVE-2026-51605 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unaut... |
| CVE-2026-51604 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth... |
| CVE-2026-51603 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth... |
| CVE-2026-51602 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth... |
| CVE-2026-51601 | HIGH | 7.5 | 0.2% | Jul 9, 2026 | Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to valid... |
| CVE-2026-51600 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIB... |
| CVE-2026-15308 | HIGH | 7.5 | 0.6% | Jul 9, 2026 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark... |
| CVE-2026-15190 | HIGH | 7.3 | — | Jul 9, 2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of... |
| CVE-2026-13462 | HIGH | 7.5 | — | Jul 9, 2026 | PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to ... |
| CVE-2026-59206 | HIGH | 7.1 | — | Jul 9, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with t... |
| CVE-2026-11404 | HIGH | 8.7 | 0.4% | Jul 9, 2026 | Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello... |
| CVE-2026-60109 | HIGH | 8.7 | 0.5% | Jul 9, 2026 | Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauth... |
| CVE-2026-60108 | HIGH | 8.7 | 0.4% | Jul 9, 2026 | Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthentica... |
| CVE-2026-56292 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing... |
| CVE-2026-54801 | HIGH | 8.6 | — | Jul 9, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst... |
| CVE-2026-54799 | HIGH | 8.4 | — | Jul 9, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst... |
| CVE-2026-54798 | HIGH | 7.1 | — | Jul 9, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst... |
| CVE-2026-4256 | HIGH | 8.2 | — | Jul 9, 2026 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now