2026 CVE Vulnerabilities
46,944 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55076 | HIGH | 7.4 | 0.5% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-51937 | HIGH | 7.5 | 0.4% | Jul 7, 2026 | An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsAp... |
| CVE-2026-14895 | HIGH | 7.5 | 0.2% | Jul 7, 2026 | String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtri... |
| CVE-2026-14380 | HIGH | 8.8 | 0.5% | Jul 7, 2026 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is ass... |
| CVE-2026-55418 | HIGH | 8.6 | 0.3% | Jul 7, 2026 | FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unr... |
| CVE-2026-55408 | HIGH | 8.4 | 0.2% | Jul 7, 2026 | Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution throu... |
| CVE-2026-55075 | HIGH | 7.4 | 0.5% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-54607 | HIGH | 7.7 | 0.2% | Jul 7, 2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer valid... |
| CVE-2026-54602 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates t... |
| CVE-2026-49229 | HIGH | 8.3 | 0.4% | Jul 7, 2026 | Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks f... |
| CVE-2026-49033 | HIGH | 8.4 | 0.1% | Jul 7, 2026 | The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arb... |
| CVE-2026-42958 | HIGH | 8.4 | 0.1% | Jul 7, 2026 | The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing s... |
| CVE-2026-42953 | HIGH | 8.4 | 0.1% | Jul 7, 2026 | The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program ... |
| CVE-2026-58583 | HIGH | 8.4 | 0.1% | Jul 7, 2026 | FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege esc... |
| CVE-2026-58472 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string... |
| CVE-2026-58471 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() f... |
| CVE-2026-58469 | HIGH | 8.7 | 0.4% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_s... |
| CVE-2026-57172 | HIGH | 8.3 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded de... |
| CVE-2026-55635 | HIGH | 8.7 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed ... |
| CVE-2026-55633 | HIGH | 8.7 | 0.5% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and f... |
| CVE-2026-55631 | HIGH | 7.2 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows aut... |
| CVE-2026-53751 | HIGH | 8.7 | 0.4% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation l... |
| CVE-2026-53730 | HIGH | 8.7 | 0.2% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql en... |
| CVE-2026-53729 | HIGH | 8.7 | 0.4% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (... |
| CVE-2026-53511 | HIGH | 8.5 | 0.1% | Jul 7, 2026 | calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now