2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45534 | CRITICAL | 9 | 0.4% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connecti... |
| CVE-2026-46421 | CRITICAL | 9.3 | — | Jul 15, 2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-d... |
| CVE-2026-62948 | CRITICAL | 9.6 | 0.3% | Jul 15, 2026 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN opt... |
| CVE-2026-53513 | CRITICAL | 9.6 | 0.3% | Jul 15, 2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin'... |
| CVE-2026-53512 | CRITICAL | 9.1 | 0.3% | Jul 15, 2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and ... |
| CVE-2026-50562 | CRITICAL | 9.3 | — | Jul 15, 2026 | FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, ar... |
| CVE-2026-14960 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interf... |
| CVE-2026-62378 | CRITICAL | 9 | 0.3% | Jul 15, 2026 | RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS C... |
| CVE-2026-52843 | CRITICAL | 9.3 | — | Jul 15, 2026 | Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest u... |
| CVE-2026-52842 | CRITICAL | 9.3 | — | Jul 15, 2026 | Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the en... |
| CVE-2026-20157 | CRITICAL | 9.8 | 0.1% | Jul 15, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c... |
| CVE-2026-20156 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c... |
| CVE-2026-50148 | CRITICAL | 9.1 | 0.4% | Jul 15, 2026 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.2... |
| CVE-2026-44986 | CRITICAL | 9.9 | — | Jul 15, 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitation... |
| CVE-2026-61740 | CRITICAL | 9.3 | — | Jul 15, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRA... |
| CVE-2026-61736 | CRITICAL | 9.3 | — | Jul 15, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* ... |
| CVE-2026-42533 | CRITICAL | 9.2 | 3.6% | Jul 15, 2026 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string express... |
| CVE-2026-43637 | CRITICAL | 9.1 | — | Jul 15, 2026 | Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files ou... |
| CVE-2026-61451 | CRITICAL | 9.6 | — | Jul 15, 2026 | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url fi... |
| CVE-2026-56400 | CRITICAL | 9.6 | 0.3% | Jul 15, 2026 | open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow... |
| CVE-2026-56398 | CRITICAL | 9 | 0.3% | Jul 15, 2026 | Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the ... |
| CVE-2026-13385 | CRITICAL | 9.5 | 0.1% | Jul 15, 2026 | An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows... |
| CVE-2026-5270 | CRITICAL | 9.8 | 0.2% | Jul 14, 2026 | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage... |
| CVE-2026-5269 | CRITICAL | 9.8 | 0.1% | Jul 14, 2026 | In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used fo... |
| CVE-2026-51808 | CRITICAL | 9.8 | 0.2% | Jul 14, 2026 | Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the open... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now