2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12942 | HIGH | 7.5 | 0.4% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker c... |
| CVE-2026-12733 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations. |
| CVE-2026-10545 | HIGH | 7.5 | 0.2% | Jul 30, 2026 | IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect ... |
| CVE-2026-10535 | HIGH | 7.8 | 0.1% | Jul 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc. |
| CVE-2026-9322 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 a... |
| CVE-2026-62663 | HIGH | 7.5 | — | Jul 30, 2026 | Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filt... |
| CVE-2026-54722 | HIGH | 8.7 | — | Jul 30, 2026 | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_... |
| CVE-2026-13117 | HIGH | 8.1 | 0.4% | Jul 30, 2026 | An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to tr... |
| CVE-2026-12996 | HIGH | 8.1 | 0.4% | Jul 30, 2026 | A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to poten... |
| CVE-2026-12945 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs throug... |
| CVE-2026-12932 | HIGH | 8.1 | 0.4% | Jul 30, 2026 | A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 all... |
| CVE-2026-11885 | HIGH | 8.4 | — | Jul 30, 2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A careful... |
| CVE-2026-11771 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the... |
| CVE-2026-58222 | HIGH | 8.8 | — | Jul 30, 2026 | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Do... |
| CVE-2026-57862 | HIGH | 8.5 | — | Jul 30, 2026 | Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass... |
| CVE-2026-28814 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain s... |
| CVE-2026-28813 | HIGH | 8.8 | 0.1% | Jul 30, 2026 | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommende... |
| CVE-2026-28811 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to ver... |
| CVE-2026-15658 | HIGH | 8.1 | 0.1% | Jul 30, 2026 | A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint t... |
| CVE-2026-10842 | HIGH | 7.5 | 0.3% | Jul 30, 2026 | IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 T... |
| CVE-2026-6540 | HIGH | 7.5 | 0.4% | Jul 30, 2026 | Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform UR... |
| CVE-2026-67349 | HIGH | 8.7 | 0.3% | Jul 30, 2026 | OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environm... |
| CVE-2026-67348 | HIGH | 8.6 | — | Jul 30, 2026 | Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authe... |
| CVE-2026-67346 | HIGH | 8.6 | — | Jul 30, 2026 | Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url ... |
| CVE-2026-67345 | HIGH | 8.5 | — | Jul 30, 2026 | MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in Defaul... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now