2026 CVE Vulnerabilities
53,576 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49499 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnera... |
| CVE-2026-46738 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the... |
| CVE-2026-46737 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the... |
| CVE-2026-44276 | MEDIUM | 4.4 | 0.1% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauth... |
| CVE-2026-40714 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A hig... |
| CVE-2026-40712 | HIGH | 7.2 | 0.3% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the... |
| CVE-2026-16607 | HIGH | 8.5 | — | Jul 22, 2026 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow... |
| CVE-2026-16606 | CRITICAL | 9.8 | — | Jul 22, 2026 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow... |
| CVE-2026-16552 | — | — | — | Jul 22, 2026 | Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of t... |
| CVE-2026-48029 | HIGH | 7.1 | 0.3% | Jul 22, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in Image... |
| CVE-2026-2395 | CRITICAL | 9.8 | 0.4% | Jul 22, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Info... |
| CVE-2026-14985 | HIGH | 7.8 | 0.2% | Jul 22, 2026 | The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the ... |
| CVE-2026-13321 | HIGH | 8.6 | — | Jul 22, 2026 | The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zon... |
| CVE-2026-13204 | HIGH | 7.5 | — | Jul 22, 2026 | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for on... |
| CVE-2026-12617 | HIGH | 7.5 | — | Jul 22, 2026 | The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME ... |
| CVE-2026-11721 | HIGH | 7.5 | — | Jul 22, 2026 | It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the z... |
| CVE-2026-11622 | HIGH | 7.5 | — | Jul 22, 2026 | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runawa... |
| CVE-2026-11605 | HIGH | 7.5 | — | Jul 22, 2026 | The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG reco... |
| CVE-2026-11331 | HIGH | 7.5 | — | Jul 22, 2026 | An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enou... |
| CVE-2026-10822 | MEDIUM | 6.5 | — | Jul 22, 2026 | If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequ... |
| CVE-2026-10723 | MEDIUM | 6.8 | — | Jul 22, 2026 | BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMA... |
| CVE-2026-62145 | HIGH | 7.5 | 0.4% | Jul 22, 2026 | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to exe... |
| CVE-2026-62144 | CRITICAL | 9.1 | 1.0% | Jul 22, 2026 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an... |
| CVE-2026-56444 | MEDIUM | 5.9 | 0.4% | Jul 22, 2026 | In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve... |
| CVE-2026-56416 | MEDIUM | 4.8 | 0.1% | Jul 22, 2026 | In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSI... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now