2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44182 | CRITICAL | 10 | 0.3% | Jul 16, 2026 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber... |
| CVE-2026-44181 | CRITICAL | 10 | 0.5% | Jul 16, 2026 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber... |
| CVE-2026-57075 | CRITICAL | 9.1 | 0.2% | Jul 16, 2026 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64... |
| CVE-2026-53412 | CRITICAL | 9.8 | 0.6% | Jul 16, 2026 | Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind... |
| CVE-2026-44180 | CRITICAL | 9.8 | 0.5% | Jul 16, 2026 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber... |
| CVE-2026-38158 | CRITICAL | 9.8 | 0.2% | Jul 16, 2026 | A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to acc... |
| CVE-2026-63089 | CRITICAL | 9.3 | 0.2% | Jul 16, 2026 | WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation... |
| CVE-2026-15422 | CRITICAL | 9.1 | 0.5% | Jul 16, 2026 | The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address ... |
| CVE-2026-54526 | CRITICAL | 9.9 | 0.2% | Jul 16, 2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t... |
| CVE-2026-46515 | CRITICAL | 9.3 | 0.3% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call ... |
| CVE-2026-46512 | CRITICAL | 9.9 | 0.4% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template para... |
| CVE-2026-45336 | CRITICAL | 10 | 0.4% | Jul 16, 2026 | HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring ... |
| CVE-2026-63087 | CRITICAL | 9.8 | 0.4% | Jul 16, 2026 | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a... |
| CVE-2026-57074 | CRITICAL | 9.1 | 0.2% | Jul 16, 2026 | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to ... |
| CVE-2026-57073 | CRITICAL | 9.1 | — | Jul 16, 2026 | HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to... |
| CVE-2026-46621 | CRITICAL | 9.1 | 0.7% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamica... |
| CVE-2026-46562 | CRITICAL | 9.8 | 0.6% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScrip... |
| CVE-2026-45568 | CRITICAL | 9.1 | 0.4% | Jul 16, 2026 | zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Fl... |
| CVE-2026-44632 | CRITICAL | 9.1 | 0.9% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs a... |
| CVE-2026-44596 | CRITICAL | 9.8 | 1.4% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handl... |
| CVE-2026-3031 | CRITICAL | 9.8 | 0.2% | Jul 16, 2026 | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg... |
| CVE-2026-59866 | CRITICAL | 9.3 | 1.4% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and... |
| CVE-2026-59865 | CRITICAL | 9.3 | 3.2% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInform... |
| CVE-2026-59864 | CRITICAL | 9.3 | — | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (w... |
| CVE-2026-54733 | CRITICAL | 9.3 | — | Jul 16, 2026 | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration fo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now