2026 CVE Vulnerabilities
47,538 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13054 | HIGH | 7.2 | 0.6% | Jul 3, 2026 | A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacke... |
| CVE-2026-13053 | HIGH | 7.2 | 0.6% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to exe... |
| CVE-2026-13050 | HIGH | 7.2 | 0.5% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged ... |
| CVE-2026-57100 | HIGH | 8.8 | 0.6% | Jul 2, 2026 | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to... |
| CVE-2026-54998 | HIGH | 8.8 | 0.6% | Jul 2, 2026 | Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-45499 | HIGH | 8.8 | 0.6% | Jul 2, 2026 | Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-12413 | HIGH | 7.5 | 0.6% | Jul 2, 2026 | An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation wou... |
| CVE-2026-58460 | HIGH | 7.7 | 0.1% | Jul 2, 2026 | react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious applicat... |
| CVE-2026-52192 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead... |
| CVE-2026-52191 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-52189 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-38972 | HIGH | 7.8 | 0.1% | Jul 2, 2026 | Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Not... |
| CVE-2026-38970 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The pars... |
| CVE-2026-59098 | HIGH | 7.1 | 0.2% | Jul 2, 2026 | LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic sea... |
| CVE-2026-59096 | HIGH | 8.2 | 0.2% | Jul 2, 2026 | Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document ... |
| CVE-2026-59095 | HIGH | 8.3 | 0.2% | Jul 2, 2026 | LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attacker... |
| CVE-2026-59094 | HIGH | 8.7 | 0.5% | Jul 2, 2026 | Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed docume... |
| CVE-2026-59093 | HIGH | 8.8 | 0.4% | Jul 2, 2026 | Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted... |
| CVE-2026-58578 | HIGH | 7.1 | 0.3% | Jul 2, 2026 | LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allo... |
| CVE-2026-58467 | HIGH | 8.2 | 0.4% | Jul 2, 2026 | Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated ... |
| CVE-2026-52187 | HIGH | 7.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-7311 | HIGH | 8.1 | 0.7% | Jul 2, 2026 | The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to in... |
| CVE-2026-58465 | HIGH | 8.7 | 0.6% | Jul 2, 2026 | Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 hand... |
| CVE-2026-8699 | HIGH | 7 | — | Jul 2, 2026 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5... |
| CVE-2026-55952 | HIGH | 7.5 | 0.5% | Jul 2, 2026 | The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientH... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now