2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63550 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request mess... |
| CVE-2026-63362 | HIGH | 8.2 | 1.5% | Jul 30, 2026 | An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cau... |
| CVE-2026-63035 | HIGH | 8.1 | 0.6% | Jul 30, 2026 | A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attack... |
| CVE-2026-64816 | HIGH | 7.1 | — | Jul 30, 2026 | RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_proce... |
| CVE-2026-63559 | HIGH | 8.7 | 0.4% | Jul 30, 2026 | An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to r... |
| CVE-2026-62246 | HIGH | 8.5 | 0.3% | Jul 30, 2026 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane dat... |
| CVE-2026-5846 | HIGH | 7.6 | 0.2% | Jul 30, 2026 | The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 cert... |
| CVE-2026-18064 | HIGH | 8.2 | 0.3% | Jul 30, 2026 | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a s... |
| CVE-2026-12562 | HIGH | 8.8 | 0.3% | Jul 30, 2026 | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full... |
| CVE-2026-68500 | HIGH | 7.5 | 0.4% | Jul 30, 2026 | Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli... |
| CVE-2026-55768 | HIGH | 8.7 | 0.3% | Jul 30, 2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b... |
| CVE-2026-54715 | HIGH | 7.1 | 0.3% | Jul 30, 2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b... |
| CVE-2026-67527 | HIGH | 7.6 | 0.2% | Jul 30, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} acc... |
| CVE-2026-67207 | HIGH | 8.8 | 0.3% | Jul 30, 2026 | Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authentic... |
| CVE-2026-67206 | HIGH | 8.8 | 0.4% | Jul 30, 2026 | Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticat... |
| CVE-2026-66755 | HIGH | 7.5 | 0.2% | Jul 30, 2026 | Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.... |
| CVE-2026-11536 | HIGH | 8.5 | 0.3% | Jul 30, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX conne... |
| CVE-2026-66416 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform stat... |
| CVE-2026-66415 | HIGH | 8.5 | — | Jul 30, 2026 | Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated a... |
| CVE-2026-61536 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool J... |
| CVE-2026-18245 | HIGH | 8.8 | 0.5% | Jul 30, 2026 | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authentic... |
| CVE-2026-18140 | HIGH | 8.7 | 0.4% | Jul 30, 2026 | Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy... |
| CVE-2026-15978 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two end... |
| CVE-2026-15977 | HIGH | 7.5 | 0.2% | Jul 30, 2026 | SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf... |
| CVE-2026-13444 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creatin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now