2026 CVE Vulnerabilities
45,452 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59712 | HIGH | 8.6 | 0.3% | Jul 6, 2026 | Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to ... |
| CVE-2026-57573 | HIGH | 8.6 | 0.3% | Jul 6, 2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF ... |
| CVE-2026-55727 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14... |
| CVE-2026-55574 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_ou... |
| CVE-2026-54765 | HIGH | 8.5 | 0.4% | Jul 6, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gatewa... |
| CVE-2026-54234 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal ... |
| CVE-2026-42331 | HIGH | 7.7 | 0.2% | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/u... |
| CVE-2026-25271 | HIGH | 7 | 0.1% | Jul 6, 2026 | Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between chec... |
| CVE-2026-25268 | HIGH | 8.8 | 0.1% | Jul 6, 2026 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. |
| CVE-2026-21383 | HIGH | 7.1 | 0.1% | Jul 6, 2026 | Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value fo... |
| CVE-2026-21379 | HIGH | 7.8 | 0.1% | Jul 6, 2026 | Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. |
| CVE-2026-14471 | HIGH | 8.6 | 0.3% | Jul 6, 2026 | Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-g... |
| CVE-2026-14468 | HIGH | 7.7 | 0.3% | Jul 6, 2026 | HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that... |
| CVE-2026-14536 | HIGH | 8.8 | 0.3% | Jul 6, 2026 | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack... |
| CVE-2026-9181 | HIGH | 7.5 | 0.7% | Jul 6, 2026 | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una... |
| CVE-2026-55380 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from t... |
| CVE-2026-55379 | HIGH | 7.5 | 0.4% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field f... |
| CVE-2026-54060 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into ... |
| CVE-2026-54059 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the P... |
| CVE-2026-13753 | HIGH | 7.5 | — | Jul 6, 2026 | A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmwa... |
| CVE-2026-43825 | HIGH | 7.3 | 4.8% | Jul 6, 2026 | Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document c... |
| CVE-2026-40140 | HIGH | 7.5 | 0.6% | Jul 6, 2026 | BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the ... |
| CVE-2026-40138 | HIGH | 8.1 | 0.4% | Jul 6, 2026 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Pri... |
| CVE-2026-59196 | HIGH | 7.1 | 0.3% | Jul 6, 2026 | pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoiste... |
| CVE-2026-59195 | HIGH | 8.2 | 0.2% | Jul 6, 2026 | pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependenc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now