2026 CVE Vulnerabilities
55,395 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48037 | MEDIUM | 6.3 | 0.3% | Jul 24, 2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P... |
| CVE-2026-48036 | HIGH | 8.4 | 0.3% | Jul 24, 2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P... |
| CVE-2026-48035 | HIGH | 7.1 | 0.3% | Jul 24, 2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P... |
| CVE-2026-48034 | HIGH | 8.5 | 0.3% | Jul 24, 2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P... |
| CVE-2026-48033 | HIGH | 8.4 | 0.3% | Jul 24, 2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P... |
| CVE-2026-48032 | HIGH | 8.3 | 0.3% | Jul 24, 2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P... |
| CVE-2026-48021 | CRITICAL | 9.1 | 0.1% | Jul 24, 2026 | In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA ba... |
| CVE-2026-17107 | HIGH | 8.5 | 0.3% | Jul 24, 2026 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes... |
| CVE-2026-66035 | HIGH | 7.7 | 0.3% | Jul 24, 2026 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that a... |
| CVE-2026-66034 | HIGH | 7.7 | 0.3% | Jul 24, 2026 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious S... |
| CVE-2026-66033 | HIGH | 8.7 | 0.4% | Jul 24, 2026 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ss... |
| CVE-2026-66032 | HIGH | 8.8 | 0.3% | Jul 24, 2026 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src... |
| CVE-2026-65711 | HIGH | 8.6 | 2.4% | Jul 24, 2026 | sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators t... |
| CVE-2026-65710 | HIGH | 7.1 | 0.2% | Jul 24, 2026 | sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the P... |
| CVE-2026-65709 | HIGH | 8.7 | 0.2% | Jul 24, 2026 | sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allo... |
| CVE-2026-65708 | HIGH | 8.6 | 0.2% | Jul 24, 2026 | sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated ... |
| CVE-2026-65707 | HIGH | 8.5 | 0.3% | Jul 24, 2026 | Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract ar... |
| CVE-2026-65623 | HIGH | 8.7 | 0.4% | Jul 24, 2026 | Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via C... |
| CVE-2026-66027 | HIGH | 8.7 | 0.3% | Jul 24, 2026 | Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated at... |
| CVE-2026-65693 | HIGH | 8.6 | 0.5% | Jul 24, 2026 | Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administ... |
| CVE-2026-64255 | HIGH | 8.8 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() ... |
| CVE-2026-64254 | MEDIUM | 5.5 | 0.1% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER... |
| CVE-2026-64253 | MEDIUM | 5.5 | 0.1% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() P... |
| CVE-2026-64252 | MEDIUM | 5.5 | 0.1% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: MIPS: DEC: Prevent initial console buffer from land... |
| CVE-2026-64251 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: pwrseq: core: fix use-after-free in pwrseq_debugfs_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now