2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51267 | — | — | 0.5% | Jul 28, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51266 | — | — | 0.6% | Jul 28, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51263 | — | — | 0.4% | Jul 28, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-47483 | HIGH | 8.2 | — | Jul 28, 2026 | NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could c... |
| CVE-2026-47427 | HIGH | 7.5 | 0.4% | Jul 28, 2026 | GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.... |
| CVE-2026-45293 | HIGH | 8.6 | — | Jul 28, 2026 | WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.... |
| CVE-2026-43910 | HIGH | 8.2 | 0.2% | Jul 28, 2026 | Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. Fro... |
| CVE-2026-8164 | HIGH | 7.3 | — | Jul 28, 2026 | Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desk... |
| CVE-2026-7521 | MEDIUM | 5.5 | 0.3% | Jul 28, 2026 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deleti... |
| CVE-2026-6879 | LOW | 2 | 0.4% | Jul 28, 2026 | `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index pred... |
| CVE-2026-67178 | HIGH | 7.8 | 0.5% | Jul 28, 2026 | MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-t... |
| CVE-2026-67174 | CRITICAL | 9.2 | 0.4% | Jul 28, 2026 | Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering... |
| CVE-2026-66713 | CRITICAL | 9.8 | 1.2% | Jul 28, 2026 | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Ap... |
| CVE-2026-66299 | MEDIUM | 5.3 | 0.5% | Jul 28, 2026 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache To... |
| CVE-2026-63727 | HIGH | 8.8 | — | Jul 28, 2026 | Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in th... |
| CVE-2026-51261 | — | — | 0.3% | Jul 28, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51260 | — | — | 0.3% | Jul 28, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51259 | — | — | 0.4% | Jul 28, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51254 | — | — | 0.1% | Jul 28, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51252 | — | — | 0.3% | Jul 28, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51251 | — | — | 0.3% | Jul 28, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-67173 | MEDIUM | 5.1 | 0.3% | Jul 28, 2026 | Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG i... |
| CVE-2026-66922 | MEDIUM | 5.1 | 0.3% | Jul 28, 2026 | Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-... |
| CVE-2026-66921 | MEDIUM | 6.3 | 0.3% | Jul 28, 2026 | Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpol... |
| CVE-2026-61487 | MEDIUM | 6.5 | 0.4% | Jul 28, 2026 | Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now