2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67528 | MEDIUM | 4.3 | 0.2% | Jul 30, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resol... |
| CVE-2026-65835 | MEDIUM | 6.6 | 0.2% | Jul 30, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE... |
| CVE-2026-65834 | MEDIUM | 6.8 | — | Jul 30, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMet... |
| CVE-2026-10569 | MEDIUM | 4.3 | 0.2% | Jul 30, 2026 | IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug... |
| CVE-2026-64870 | MEDIUM | 5.3 | — | Jul 30, 2026 | MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool p... |
| CVE-2026-59881 | MEDIUM | 6.9 | — | Jul 30, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client ac... |
| CVE-2026-15974 | MEDIUM | 6.5 | 0.2% | Jul 30, 2026 | SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitize... |
| CVE-2026-14227 | MEDIUM | 6.9 | — | Jul 30, 2026 | An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Sessi... |
| CVE-2026-11904 | MEDIUM | 5.3 | 0.3% | Jul 30, 2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident... |
| CVE-2026-10700 | MEDIUM | 6.5 | 0.4% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API th... |
| CVE-2026-10695 | MEDIUM | 5.5 | 0.1% | Jul 30, 2026 | IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated qu... |
| CVE-2026-66414 | MEDIUM | 6.1 | — | Jul 30, 2026 | Leantime 3.6.2 contains an open redirect vulnerability in the Login controller that allows unauthenticated attackers to ... |
| CVE-2026-54522 | MEDIUM | 5.4 | 0.1% | Jul 30, 2026 | MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::B... |
| CVE-2026-67596 | MEDIUM | 6.9 | — | Jul 30, 2026 | CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticate... |
| CVE-2026-58216 | MEDIUM | 5.3 | 0.5% | Jul 30, 2026 | An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi... |
| CVE-2026-48910 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the mar... |
| CVE-2026-44617 | MEDIUM | 6.5 | 0.4% | Jul 30, 2026 | LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constru... |
| CVE-2026-44616 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escap... |
| CVE-2026-44613 | MEDIUM | 6.1 | 0.4% | Jul 30, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin ... |
| CVE-2026-23985 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The... |
| CVE-2026-23981 | MEDIUM | 4.3 | 0.3% | Jul 30, 2026 | An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to upd... |
| CVE-2026-15657 | MEDIUM | 6.5 | 0.1% | Jul 30, 2026 | A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor mercha... |
| CVE-2026-67347 | MEDIUM | 6.8 | — | Jul 30, 2026 | Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-loc... |
| CVE-2026-54885 | MEDIUM | 6.9 | — | Jul 30, 2026 | Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAu... |
| CVE-2026-41187 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Dele... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now