2026 CVE Vulnerabilities
51,080 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15977 | HIGH | 7.5 | 0.2% | Jul 30, 2026 | SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf... |
| CVE-2026-15976 | CRITICAL | 9.8 | 0.3% | Jul 30, 2026 | SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wi... |
| CVE-2026-15974 | MEDIUM | 6.5 | 0.2% | Jul 30, 2026 | SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitize... |
| CVE-2026-15971 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when D... |
| CVE-2026-15969 | CRITICAL | 9.8 | 1.0% | Jul 30, 2026 | SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl... |
| CVE-2026-14227 | MEDIUM | 6.9 | — | Jul 30, 2026 | An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Sessi... |
| CVE-2026-13444 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creatin... |
| CVE-2026-13435 | CRITICAL | 9.9 | 0.3% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox impl... |
| CVE-2026-12943 | CRITICAL | 9.8 | 0.9% | Jul 30, 2026 | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power en... |
| CVE-2026-12942 | HIGH | 7.5 | 0.4% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker c... |
| CVE-2026-12733 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations. |
| CVE-2026-12118 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary co... |
| CVE-2026-11904 | MEDIUM | 5.3 | 0.3% | Jul 30, 2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident... |
| CVE-2026-10700 | MEDIUM | 6.5 | 0.4% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API th... |
| CVE-2026-10695 | MEDIUM | 5.5 | 0.1% | Jul 30, 2026 | IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated qu... |
| CVE-2026-10545 | HIGH | 7.5 | 0.2% | Jul 30, 2026 | IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect ... |
| CVE-2026-10535 | HIGH | 7.8 | 0.1% | Jul 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. |
| CVE-2026-9322 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 a... |
| CVE-2026-66414 | MEDIUM | 6.1 | — | Jul 30, 2026 | Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to ... |
| CVE-2026-62663 | HIGH | 7.5 | — | Jul 30, 2026 | Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filt... |
| CVE-2026-54722 | HIGH | 8.7 | — | Jul 30, 2026 | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_... |
| CVE-2026-54522 | MEDIUM | 5.4 | 0.1% | Jul 30, 2026 | MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::B... |
| CVE-2026-51295 | — | — | 0.2% | Jul 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51294 | — | — | 0.1% | Jul 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51293 | — | — | 0.1% | Jul 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now