2026 CVE Vulnerabilities
46,876 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35552 | HIGH | 8.1 | 0.2% | Jul 8, 2026 | In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remot... |
| CVE-2026-10037 | HIGH | 8.8 | 0.1% | Jul 8, 2026 | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by th... |
| CVE-2026-60105 | HIGH | 8.6 | 0.3% | Jul 8, 2026 | Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an... |
| CVE-2026-59818 | HIGH | 8.1 | 0.4% | Jul 8, 2026 | etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is con... |
| CVE-2026-58525 | HIGH | 8.2 | 0.4% | Jul 8, 2026 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature ... |
| CVE-2026-58208 | HIGH | 7.5 | 0.5% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58192 | HIGH | 8.6 | 0.3% | Jul 8, 2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior... |
| CVE-2026-57480 | HIGH | 8.7 | 0.3% | Jul 8, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a... |
| CVE-2026-56669 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun... |
| CVE-2026-55596 | HIGH | 8.7 | 0.2% | Jul 8, 2026 | Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized ... |
| CVE-2026-55206 | HIGH | 8.7 | 0.3% | Jul 8, 2026 | py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio... |
| CVE-2026-55195 | HIGH | 8.7 | 0.3% | Jul 8, 2026 | py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio... |
| CVE-2026-54591 | HIGH | 8.1 | 0.3% | Jul 8, 2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to... |
| CVE-2026-54528 | HIGH | 7.1 | 0.3% | Jul 8, 2026 | JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandl... |
| CVE-2026-49866 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLim... |
| CVE-2026-35210 | HIGH | 7.1 | 0.3% | Jul 8, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0... |
| CVE-2026-15169 | HIGH | 7.5 | 0.1% | Jul 8, 2026 | UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service |
| CVE-2026-15163 | HIGH | 7.5 | 0.1% | Jul 8, 2026 | Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service |
| CVE-2026-0288 | HIGH | 7.5 | 0.8% | Jul 8, 2026 | Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-... |
| CVE-2026-8800 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transf... |
| CVE-2026-8651 | HIGH | 7.5 | 0.2% | Jul 8, 2026 | Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects ... |
| CVE-2026-8650 | HIGH | 7.5 | 0.2% | Jul 8, 2026 | Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Tr... |
| CVE-2026-60104 | HIGH | 8 | 0.2% | Jul 8, 2026 | Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to t... |
| CVE-2026-59948 | HIGH | 7 | 0.1% | Jul 8, 2026 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an... |
| CVE-2026-59939 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now