2026 CVE Vulnerabilities
53,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66390 | MEDIUM | 6.1 | 0.2% | Jul 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th... |
| CVE-2026-63077 | CRITICAL | 9.8 | 0.6% | Jul 27, 2026 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin... |
| CVE-2026-24252 | HIGH | 7.8 | 0.7% | Jul 27, 2026 | NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of... |
| CVE-2026-17531 | MEDIUM | 5 | 0.2% | Jul 27, 2026 | A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality... |
| CVE-2026-17192 | HIGH | 8.5 | 2.3% | Jul 27, 2026 | A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authentica... |
| CVE-2026-17191 | CRITICAL | 9.1 | 2.8% | Jul 27, 2026 | An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this... |
| CVE-2026-66399 | HIGH | 8.5 | 0.2% | Jul 27, 2026 | phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows admi... |
| CVE-2026-66398 | CRITICAL | 9.4 | 0.2% | Jul 27, 2026 | phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated... |
| CVE-2026-66397 | HIGH | 8.6 | 0.3% | Jul 27, 2026 | phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, al... |
| CVE-2026-66396 | CRITICAL | 9.3 | 0.3% | Jul 27, 2026 | SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cov... |
| CVE-2026-66395 | CRITICAL | 9.6 | 0.3% | Jul 27, 2026 | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler... |
| CVE-2026-66394 | CRITICAL | 9.3 | 0.3% | Jul 27, 2026 | SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows ... |
| CVE-2026-59251 | HIGH | 7.5 | 0.3% | Jul 27, 2026 | Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthentica... |
| CVE-2026-59250 | HIGH | 8.3 | 0.7% | Jul 27, 2026 | Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corru... |
| CVE-2026-58227 | HIGH | 7.5 | 0.4% | Jul 27, 2026 | The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a ... |
| CVE-2026-55953 | HIGH | 7.4 | 0.2% | Jul 27, 2026 | The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in... |
| CVE-2026-55737 | HIGH | 7.5 | 0.1% | Jul 27, 2026 | Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can ... |
| CVE-2026-54890 | HIGH | 7.5 | 0.3% | Jul 27, 2026 | Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modu... |
| CVE-2026-51304 | — | — | 0.3% | Jul 27, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51303 | — | — | 0.4% | Jul 27, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51302 | — | — | 0.4% | Jul 27, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51300 | — | — | 0.4% | Jul 27, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51298 | — | — | 0.1% | Jul 27, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51297 | — | — | 0.3% | Jul 27, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51296 | — | — | 0.3% | Jul 27, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now