2026 CVE Vulnerabilities
51,043 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18394 | HIGH | 7.4 | 0.3% | Jul 31, 2026 | Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to ob... |
| CVE-2026-57232 | LOW | 3.1 | 0.2% | Jul 31, 2026 | Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end mod... |
| CVE-2026-55824 | LOW | 2.6 | — | Jul 31, 2026 | Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth cre... |
| CVE-2026-53505 | HIGH | 7.5 | 0.3% | Jul 31, 2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) fi... |
| CVE-2026-53504 | HIGH | 7.5 | — | Jul 31, 2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expressio... |
| CVE-2026-53503 | HIGH | 7.5 | — | Jul 31, 2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, ... |
| CVE-2026-53502 | HIGH | 8.7 | — | Jul 31, 2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path... |
| CVE-2026-53501 | HIGH | 8.2 | — | Jul 31, 2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypasse... |
| CVE-2026-53500 | HIGH | 8.2 | — | Jul 31, 2026 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes... |
| CVE-2026-25552 | LOW | 3.7 | — | Jul 31, 2026 | Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rat... |
| CVE-2026-18481 | HIGH | 7.3 | 0.3% | Jul 31, 2026 | Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticate... |
| CVE-2026-18321 | MEDIUM | 4.7 | 0.1% | Jul 31, 2026 | Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd |
| CVE-2026-55100 | HIGH | 8.7 | — | Jul 31, 2026 | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenat... |
| CVE-2026-54737 | HIGH | 7.3 | — | Jul 31, 2026 | @phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to ... |
| CVE-2026-54729 | HIGH | 8.7 | — | Jul 31, 2026 | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_... |
| CVE-2026-54725 | CRITICAL | 9.6 | — | Jul 31, 2026 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1... |
| CVE-2026-34497 | MEDIUM | 5.4 | 0.4% | Jul 31, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste... |
| CVE-2026-34495 | MEDIUM | 5.4 | 0.4% | Jul 31, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F... |
| CVE-2026-34490 | MEDIUM | 5.5 | 0.1% | Jul 31, 2026 | Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac... |
| CVE-2026-21662 | CRITICAL | 9.8 | 0.4% | Jul 31, 2026 | Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malic... |
| CVE-2026-67822 | CRITICAL | 9.8 | — | Jul 31, 2026 | Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu... |
| CVE-2026-58048 | CRITICAL | 9.4 | 0.6% | Jul 31, 2026 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. |
| CVE-2026-58047 | MEDIUM | 5.6 | 0.5% | Jul 31, 2026 | HTTP Smuggling in cPanel allows potential leak of credentials. |
| CVE-2026-54707 | MEDIUM | 5.4 | — | Jul 31, 2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien... |
| CVE-2026-54706 | MEDIUM | 4.8 | — | Jul 31, 2026 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now