2026 CVE Vulnerabilities
46,863 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0287 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with... |
| CVE-2026-0286 | HIGH | 7.2 | 1.0% | Jul 9, 2026 | A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticate... |
| CVE-2026-0283 | HIGH | 7.2 | 0.2% | Jul 9, 2026 | An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software a... |
| CVE-2026-0281 | HIGH | 7.1 | 0.2% | Jul 9, 2026 | An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with ... |
| CVE-2026-0280 | HIGH | 7.2 | 0.2% | Jul 9, 2026 | An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticat... |
| CVE-2026-61343 | HIGH | 8.6 | 0.8% | Jul 9, 2026 | LibreBooking's email template editor save action passes the submitted template name directly into the destination file p... |
| CVE-2026-59827 | HIGH | 8.8 | 0.4% | Jul 9, 2026 | Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1... |
| CVE-2026-59734 | HIGH | 8.8 | — | Jul 9, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-59721 | HIGH | 7.2 | 0.5% | Jul 9, 2026 | Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in ad... |
| CVE-2026-59720 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.t... |
| CVE-2026-59221 | HIGH | 7.7 | — | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitiz... |
| CVE-2026-58378 | HIGH | 8.8 | 0.2% | Jul 9, 2026 | Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB a... |
| CVE-2026-55420 | HIGH | 8.1 | 0.3% | Jul 9, 2026 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-... |
| CVE-2026-59224 | HIGH | 8 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webu... |
| CVE-2026-59219 | HIGH | 7.1 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redi... |
| CVE-2026-53987 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban ba... |
| CVE-2026-51606 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device t... |
| CVE-2026-51605 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unaut... |
| CVE-2026-51604 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth... |
| CVE-2026-51603 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth... |
| CVE-2026-51602 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth... |
| CVE-2026-51601 | HIGH | 7.5 | 0.2% | Jul 9, 2026 | Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to valid... |
| CVE-2026-51600 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIB... |
| CVE-2026-15308 | HIGH | 7.5 | 0.6% | Jul 9, 2026 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark... |
| CVE-2026-15190 | HIGH | 7.3 | — | Jul 9, 2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now