2026 CVE Vulnerabilities
46,946 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58472 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string... |
| CVE-2026-58471 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() f... |
| CVE-2026-58469 | HIGH | 8.7 | 0.4% | Jul 7, 2026 | GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_s... |
| CVE-2026-57172 | HIGH | 8.3 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded de... |
| CVE-2026-55635 | HIGH | 8.7 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed ... |
| CVE-2026-55633 | HIGH | 8.7 | 0.5% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and f... |
| CVE-2026-55631 | HIGH | 7.2 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows aut... |
| CVE-2026-53751 | HIGH | 8.7 | 0.4% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation l... |
| CVE-2026-53730 | HIGH | 8.7 | 0.2% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql en... |
| CVE-2026-53729 | HIGH | 8.7 | 0.4% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (... |
| CVE-2026-53511 | HIGH | 8.5 | 0.1% | Jul 7, 2026 | calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when... |
| CVE-2026-50530 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface onl... |
| CVE-2026-50529 | HIGH | 8.7 | 0.3% | Jul 7, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share int... |
| CVE-2026-50007 | HIGH | 7.2 | 0.2% | Jul 7, 2026 | Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared us... |
| CVE-2026-49471 | HIGH | 8.3 | 0.2% | Jul 7, 2026 | Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, ... |
| CVE-2026-44454 | HIGH | 8.8 | 2.3% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30... |
| CVE-2026-7017 | HIGH | 7.1 | 0.3% | Jul 7, 2026 | HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server ... |
| CVE-2026-59708 | HIGH | 8.7 | 0.3% | Jul 7, 2026 | The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeU... |
| CVE-2026-48958 | HIGH | 8.8 | 0.3% | Jul 7, 2026 | An improper access check allows unauthorized users to create custom fields via webservices endpoints. |
| CVE-2026-48957 | HIGH | 8.8 | 0.3% | Jul 7, 2026 | An improper access check allows unauthorized users to access com_privacy datasets. |
| CVE-2026-48948 | HIGH | 8.8 | 0.3% | Jul 7, 2026 | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. |
| CVE-2026-57851 | HIGH | 8.5 | 0.2% | Jul 7, 2026 | MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allo... |
| CVE-2026-23698 | HIGH | 8.6 | 0.9% | Jul 7, 2026 | Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import featur... |
| CVE-2026-23697 | HIGH | 8.8 | 0.8% | Jul 7, 2026 | Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve ... |
| CVE-2026-14904 | HIGH | 7.1 | 0.4% | Jul 7, 2026 | AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now