2026 CVE Vulnerabilities
51,094 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67596 | MEDIUM | 6.9 | — | Jul 30, 2026 | CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticate... |
| CVE-2026-58222 | HIGH | 8.8 | — | Jul 30, 2026 | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Do... |
| CVE-2026-58216 | MEDIUM | 5.3 | 0.5% | Jul 30, 2026 | An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi... |
| CVE-2026-57862 | HIGH | 8.5 | — | Jul 30, 2026 | Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass... |
| CVE-2026-52680 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary... |
| CVE-2026-4978 | CRITICAL | 9.8 | — | Jul 30, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffi... |
| CVE-2026-48910 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the mar... |
| CVE-2026-44617 | MEDIUM | 6.5 | 0.4% | Jul 30, 2026 | LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constru... |
| CVE-2026-44616 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escap... |
| CVE-2026-44613 | MEDIUM | 6.1 | 0.4% | Jul 30, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin ... |
| CVE-2026-28814 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain s... |
| CVE-2026-28813 | HIGH | 8.8 | 0.1% | Jul 30, 2026 | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommende... |
| CVE-2026-28812 | CRITICAL | 9.8 | 0.3% | Jul 30, 2026 | UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate pri... |
| CVE-2026-28811 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to ver... |
| CVE-2026-28323 | CRITICAL | 9.8 | 0.6% | Jul 30, 2026 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2... |
| CVE-2026-23985 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The... |
| CVE-2026-23981 | MEDIUM | 4.3 | 0.3% | Jul 30, 2026 | An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to upd... |
| CVE-2026-15658 | HIGH | 8.1 | 0.1% | Jul 30, 2026 | A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint t... |
| CVE-2026-15657 | MEDIUM | 6.5 | 0.1% | Jul 30, 2026 | A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor mercha... |
| CVE-2026-10842 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 T... |
| CVE-2026-6540 | HIGH | 7.5 | 0.4% | Jul 30, 2026 | Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform UR... |
| CVE-2026-67349 | HIGH | 8.7 | 0.3% | Jul 30, 2026 | OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environm... |
| CVE-2026-67348 | HIGH | 8.6 | — | Jul 30, 2026 | Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authe... |
| CVE-2026-67347 | MEDIUM | 6.8 | — | Jul 30, 2026 | Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-loc... |
| CVE-2026-67346 | HIGH | 8.6 | — | Jul 30, 2026 | Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now