2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27780 | CRITICAL | 9.8 | 0.2% | Jul 3, 2026 | Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowin... |
| CVE-2026-26292 | CRITICAL | 9.8 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing ... |
| CVE-2026-26247 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowi... |
| CVE-2026-26232 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during... |
| CVE-2026-25718 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi... |
| CVE-2026-22874 | CRITICAL | 9.6 | 0.5% | Jul 3, 2026 | Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. |
| CVE-2026-22547 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa... |
| CVE-2026-20896 | CRITICAL | 9.8 | 0.8% | Jul 3, 2026 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour... |
| CVE-2026-20706 | CRITICAL | 9.1 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc... |
| CVE-2026-12481 | CRITICAL | 9.8 | 0.4% | Jul 3, 2026 | A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser... |
| CVE-2026-56015 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passe... |
| CVE-2026-4321 | CRITICAL | 9.8 | 0.3% | Jul 3, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web... |
| CVE-2026-47898 | CRITICAL | 9.8 | 0.1% | Jul 3, 2026 | Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common lib... |
| CVE-2026-14544 | CRITICAL | 9.8 | 0.5% | Jul 3, 2026 | A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8... |
| CVE-2026-9079 | CRITICAL | 9.8 | 0.8% | Jul 3, 2026 | libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the o... |
| CVE-2026-8927 | CRITICAL | 9.1 | 0.3% | Jul 3, 2026 | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails... |
| CVE-2026-8926 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(withou... |
| CVE-2026-8925 | CRITICAL | 9.8 | 0.2% | Jul 3, 2026 | The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing t... |
| CVE-2026-8924 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffi... |
| CVE-2026-11856 | CRITICAL | 9.8 | 0.8% | Jul 3, 2026 | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then ... |
| CVE-2026-11564 | CRITICAL | 9.1 | 0.5% | Jul 3, 2026 | libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches ... |
| CVE-2026-10536 | CRITICAL | 9.8 | 0.6% | Jul 3, 2026 | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CU... |
| CVE-2026-9725 | CRITICAL | 9.1 | 0.7% | Jul 3, 2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletio... |
| CVE-2026-13768 | CRITICAL | 10 | 0.6% | Jul 3, 2026 | Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub R... |
| CVE-2026-13368 | CRITICAL | 9.2 | 0.8% | Jul 3, 2026 | WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now