2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5491 | HIGH | 7.5 | — | Jul 29, 2026 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo... |
| CVE-2026-5490 | HIGH | 8.8 | 0.5% | Jul 29, 2026 | DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privi... |
| CVE-2026-5487 | HIGH | 7.5 | — | Jul 29, 2026 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo... |
| CVE-2026-5057 | HIGH | 7.5 | — | Jul 29, 2026 | ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attacke... |
| CVE-2026-5056 | HIGH | 7.8 | — | Jul 29, 2026 | GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote atta... |
| CVE-2026-18022 | HIGH | 8.8 | 0.3% | Jul 29, 2026 | Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, w... |
| CVE-2026-15975 | HIGH | 7.5 | 0.4% | Jul 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 1... |
| CVE-2026-13268 | HIGH | 7.8 | — | Jul 29, 2026 | G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows ... |
| CVE-2026-12436 | HIGH | 8.4 | 0.3% | Jul 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 1... |
| CVE-2026-12357 | HIGH | 7.2 | — | Jul 29, 2026 | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2026-67428 | HIGH | 8.5 | 0.3% | Jul 29, 2026 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules includi... |
| CVE-2026-67427 | HIGH | 8.6 | 0.3% | Jul 29, 2026 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable ... |
| CVE-2026-67425 | HIGH | 8.6 | 0.3% | Jul 29, 2026 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys ... |
| CVE-2026-67424 | HIGH | 8.5 | 0.2% | Jul 29, 2026 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, ht... |
| CVE-2026-67201 | HIGH | 8.6 | 0.4% | Jul 29, 2026 | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows... |
| CVE-2026-59898 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,... |
| CVE-2026-2482 | HIGH | 8.8 | 0.1% | Jul 29, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which c... |
| CVE-2026-16328 | HIGH | 8.6 | — | Jul 29, 2026 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing ... |
| CVE-2026-12935 | HIGH | 8.7 | — | Jul 29, 2026 | The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based b... |
| CVE-2026-8497 | HIGH | 7.4 | 0.1% | Jul 29, 2026 | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0... |
| CVE-2026-59901 | HIGH | 7.5 | 0.2% | Jul 29, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ... |
| CVE-2026-59899 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ... |
| CVE-2026-40272 | HIGH | 7 | 0.1% | Jul 29, 2026 | Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted k... |
| CVE-2026-14266 | HIGH | 7.8 | 0.9% | Jul 29, 2026 | 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote ... |
| CVE-2026-8339 | HIGH | 8.7 | 0.2% | Jul 29, 2026 | A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclus... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now