2026 CVE Vulnerabilities
46,856 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59856 | HIGH | 7.8 | 0.2% | Jul 9, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/p... |
| CVE-2026-59855 | HIGH | 8.6 | 0.3% | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts in... |
| CVE-2026-59834 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/searc... |
| CVE-2026-59833 | HIGH | 8.6 | 0.4% | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content t... |
| CVE-2026-59832 | HIGH | 7.7 | 0.3% | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler ser... |
| CVE-2026-33655 | HIGH | 7.7 | 0.4% | Jul 9, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0... |
| CVE-2026-58143 | HIGH | 8.8 | 0.2% | Jul 9, 2026 | Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attacke... |
| CVE-2026-57032 | HIGH | 7.1 | 0.4% | Jul 9, 2026 | An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Jun... |
| CVE-2026-57030 | HIGH | 8.2 | 0.4% | Jul 9, 2026 | A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packe... |
| CVE-2026-57028 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve... |
| CVE-2026-57027 | HIGH | 7.1 | 0.3% | Jul 9, 2026 | A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Netw... |
| CVE-2026-57026 | HIGH | 8.7 | 0.5% | Jul 9, 2026 | An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on... |
| CVE-2026-57023 | HIGH | 8.7 | 0.5% | Jul 9, 2026 | An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS... |
| CVE-2026-57022 | HIGH | 8.2 | 0.4% | Jul 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper N... |
| CVE-2026-57020 | HIGH | 7.1 | 0.3% | Jul 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper N... |
| CVE-2026-57019 | HIGH | 7.1 | 0.3% | Jul 9, 2026 | An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Net... |
| CVE-2026-55689 | HIGH | 8.1 | 0.3% | Jul 9, 2026 | OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skippe... |
| CVE-2026-55604 | HIGH | 8.6 | 0.2% | Jul 9, 2026 | DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-... |
| CVE-2026-49256 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and... |
| CVE-2026-45788 | HIGH | 7.5 | 0.5% | Jul 9, 2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads cou... |
| CVE-2026-44787 | HIGH | 7.1 | 0.3% | Jul 9, 2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow co... |
| CVE-2026-39246 | HIGH | 7.5 | 0.5% | Jul 9, 2026 | decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (ty... |
| CVE-2026-38076 | HIGH | 7.5 | 0.2% | Jul 9, 2026 | An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Deni... |
| CVE-2026-15271 | HIGH | 7.7 | 0.4% | Jul 9, 2026 | A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 u... |
| CVE-2026-55865 | HIGH | 7.1 | 0.5% | Jul 9, 2026 | Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag with... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now