2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55403 | LOW | 3.7 | 0.2% | Jul 28, 2026 | datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_gener... |
| CVE-2026-54620 | LOW | 2 | 0.1% | Jul 28, 2026 | sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite agg... |
| CVE-2026-54619 | LOW | 2 | 0.1% | Jul 28, 2026 | sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite func... |
| CVE-2026-6879 | LOW | 2 | 0.3% | Jul 28, 2026 | `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index pred... |
| CVE-2026-18028 | LOW | 2.3 | 0.2% | Jul 28, 2026 | The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of ... |
| CVE-2026-17072 | LOW | 3.3 | — | Jul 28, 2026 | A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC... |
| CVE-2026-55977 | LOW | 3.3 | 0.1% | Jul 28, 2026 | Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the applicatio... |
| CVE-2026-14821 | LOW | 2.7 | 0.1% | Jul 28, 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting out... |
| CVE-2026-14819 | LOW | 3.5 | 0.2% | Jul 28, 2026 | The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputtin... |
| CVE-2026-64745 | LOW | 2.4 | 0.2% | Jul 27, 2026 | This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, m... |
| CVE-2026-59730 | LOW | 2.1 | 0.4% | Jul 27, 2026 | Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailingSlash: 'always' is ... |
| CVE-2026-59727 | LOW | 2.1 | 0.3% | Jul 27, 2026 | Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, trans... |
| CVE-2026-48051 | LOW | 3.5 | 0.2% | Jul 27, 2026 | Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery sy... |
| CVE-2026-17513 | LOW | 3.3 | — | Jul 27, 2026 | A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file... |
| CVE-2026-56538 | LOW | 3.5 | 0.2% | Jul 27, 2026 | An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosi... |
| CVE-2026-56537 | LOW | 3.5 | 0.2% | Jul 27, 2026 | HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar... |
| CVE-2026-17512 | LOW | 3.3 | — | Jul 27, 2026 | A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the fi... |
| CVE-2026-40000 | LOW | 1.8 | 0.3% | Jul 27, 2026 | The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compre... |
| CVE-2026-14189 | LOW | 3.8 | — | Jul 27, 2026 | The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them ... |
| CVE-2026-66011 | LOW | 3.3 | 0.1% | Jul 25, 2026 | ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid optio... |
| CVE-2026-17039 | LOW | 3.1 | — | Jul 24, 2026 | A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based autho... |
| CVE-2026-55728 | LOW | 3.8 | 0.1% | Jul 24, 2026 | Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L... |
| CVE-2026-56392 | LOW | 1.8 | 0.1% | Jul 24, 2026 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation... |
| CVE-2026-12690 | LOW | 3.8 | 0.1% | Jul 24, 2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, ... |
| CVE-2026-15687 | LOW | 2.4 | — | Jul 23, 2026 | A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now