2026 CVE Vulnerabilities
51,085 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54722 | HIGH | 8.7 | — | Jul 30, 2026 | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_... |
| CVE-2026-54522 | MEDIUM | 5.4 | 0.1% | Jul 30, 2026 | MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::B... |
| CVE-2026-51295 | — | — | 0.2% | Jul 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51294 | — | — | 0.1% | Jul 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51293 | — | — | 0.1% | Jul 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51292 | — | — | 0.3% | Jul 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51291 | — | — | 0.3% | Jul 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51290 | — | — | 0.3% | Jul 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-13379 | CRITICAL | 9.1 | 0.3% | Jul 30, 2026 | The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS stat... |
| CVE-2026-13117 | HIGH | 8.1 | 0.4% | Jul 30, 2026 | An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to tr... |
| CVE-2026-12996 | HIGH | 8.1 | 0.4% | Jul 30, 2026 | A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to poten... |
| CVE-2026-12945 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs throug... |
| CVE-2026-12940 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable ... |
| CVE-2026-12932 | HIGH | 8.1 | 0.4% | Jul 30, 2026 | A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 all... |
| CVE-2026-11885 | HIGH | 8.4 | — | Jul 30, 2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A careful... |
| CVE-2026-11771 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the... |
| CVE-2026-67596 | MEDIUM | 6.9 | — | Jul 30, 2026 | CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticate... |
| CVE-2026-58222 | HIGH | 8.8 | — | Jul 30, 2026 | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Do... |
| CVE-2026-58216 | MEDIUM | 5.3 | 0.5% | Jul 30, 2026 | An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi... |
| CVE-2026-57862 | HIGH | 8.5 | — | Jul 30, 2026 | Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass... |
| CVE-2026-52680 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary... |
| CVE-2026-4978 | CRITICAL | 9.8 | — | Jul 30, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffi... |
| CVE-2026-48910 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the mar... |
| CVE-2026-44617 | MEDIUM | 6.5 | 0.4% | Jul 30, 2026 | LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constru... |
| CVE-2026-44616 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escap... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now