2026 CVE Vulnerabilities
47,646 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13760 | HIGH | 7.3 | — | Jul 1, 2026 | OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platfor... |
| CVE-2026-57736 | HIGH | 7.4 | — | Jul 1, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. Thi... |
| CVE-2026-57723 | HIGH | 7.4 | — | Jul 1, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal.... |
| CVE-2026-54428 | HIGH | 7.5 | 0.6% | Jul 1, 2026 | Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 an... |
| CVE-2026-49091 | HIGH | 8 | 0.2% | Jul 1, 2026 | Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forgin... |
| CVE-2026-46680 | HIGH | 7.8 | 0.2% | Jul 1, 2026 | containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched... |
| CVE-2026-58454 | HIGH | 7.7 | 0.5% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that ... |
| CVE-2026-58452 | HIGH | 8.8 | 2.4% | Jul 1, 2026 | JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that ... |
| CVE-2026-57516 | HIGH | 8.8 | 0.5% | Jul 1, 2026 | Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to a... |
| CVE-2026-56150 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Exces... |
| CVE-2026-54399 | HIGH | 7.5 | 0.6% | Jul 1, 2026 | Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and ... |
| CVE-2026-20244 | HIGH | 7.5 | 0.4% | Jul 1, 2026 | A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c... |
| CVE-2026-20243 | HIGH | 7.5 | 0.4% | Jul 1, 2026 | A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c... |
| CVE-2026-20217 | HIGH | 7.5 | 0.4% | Jul 1, 2026 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do... |
| CVE-2026-20216 | HIGH | 7.5 | 0.4% | Jul 1, 2026 | A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cau... |
| CVE-2026-20215 | HIGH | 7.5 | 0.4% | Jul 1, 2026 | A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co... |
| CVE-2026-20214 | HIGH | 7.5 | 0.5% | Jul 1, 2026 | A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c... |
| CVE-2026-20213 | HIGH | 7.5 | 0.5% | Jul 1, 2026 | A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co... |
| CVE-2026-20191 | HIGH | 7.5 | — | Jul 1, 2026 | A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a ... |
| CVE-2026-8857 | HIGH | 8.8 | 0.3% | Jul 1, 2026 | A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTime... |
| CVE-2026-58036 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne... |
| CVE-2026-24266 | HIGH | 7.5 | 0.5% | Jul 1, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A ... |
| CVE-2026-24264 | HIGH | 7.5 | 0.7% | Jul 1, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highl... |
| CVE-2026-24260 | HIGH | 8.5 | — | Jul 1, 2026 | NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use ra... |
| CVE-2026-24251 | HIGH | 7.8 | — | Jul 1, 2026 | NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now