2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59706 | CRITICAL | 9.3 | 0.3% | Jul 7, 2026 | mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f... |
| CVE-2026-46354 | CRITICAL | 9.1 | 0.3% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29... |
| CVE-2026-59707 | CRITICAL | 9.2 | 0.4% | Jul 7, 2026 | LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that al... |
| CVE-2026-58473 | CRITICAL | 9.3 | 0.4% | Jul 7, 2026 | Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite... |
| CVE-2026-59800 | CRITICAL | 9.8 | 1.4% | Jul 7, 2026 | 9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-i... |
| CVE-2026-13020 | CRITICAL | 9.8 | 0.2% | Jul 7, 2026 | A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on ... |
| CVE-2026-13019 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit... |
| CVE-2026-53483 | CRITICAL | 9.8 | 0.6% | Jul 7, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-53481 | CRITICAL | 9.8 | 0.6% | Jul 7, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-33264 | CRITICAL | 9.8 | 1.1% | Jul 7, 2026 | A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths whe... |
| CVE-2026-4375 | CRITICAL | 9 | 0.2% | Jul 7, 2026 | The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to... |
| CVE-2026-14345 | CRITICAL | 9.8 | 0.7% | Jul 7, 2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Re... |
| CVE-2026-12375 | CRITICAL | 9.8 | 0.1% | Jul 7, 2026 | The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny... |
| CVE-2026-34048 | CRITICAL | 9.9 | 0.4% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34047 | CRITICAL | 9.9 | 0.4% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34037 | CRITICAL | 9.9 | 0.2% | Jul 7, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-57572 | CRITICAL | 10 | 0.5% | Jul 6, 2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-... |
| CVE-2026-57571 | CRITICAL | 9.6 | 0.5% | Jul 6, 2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded fil... |
| CVE-2026-54763 | CRITICAL | 10 | 0.3% | Jul 6, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestA... |
| CVE-2026-42341 | CRITICAL | 9.2 | 0.2% | Jul 6, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenti... |
| CVE-2026-34038 | CRITICAL | 9.9 | — | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-11405 | CRITICAL | 9.8 | 0.2% | Jul 6, 2026 | The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8... |
| CVE-2026-9182 | CRITICAL | 9.8 | 0.3% | Jul 6, 2026 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is... |
| CVE-2026-48614 | CRITICAL | 9.9 | — | Jul 6, 2026 | An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configurat... |
| CVE-2026-48316 | CRITICAL | 10 | 1.4% | Jul 6, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now