2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67194 | HIGH | 7.1 | 0.3% | Jul 29, 2026 | Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process... |
| CVE-2026-64560 | HIGH | 7.8 | — | Jul 29, 2026 | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader ... |
| CVE-2026-64559 | HIGH | 7.8 | — | Jul 29, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl ... |
| CVE-2026-64558 | HIGH | 7.8 | — | Jul 29, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler imple... |
| CVE-2026-54727 | HIGH | 8.2 | 0.1% | Jul 29, 2026 | proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink ... |
| CVE-2026-54693 | HIGH | 8.2 | 0.3% | Jul 29, 2026 | ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4... |
| CVE-2026-54574 | HIGH | 8.2 | 0.1% | Jul 29, 2026 | proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain ta... |
| CVE-2026-18255 | HIGH | 7.2 | — | Jul 29, 2026 | A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repo... |
| CVE-2026-54079 | HIGH | 8.7 | 0.3% | Jul 29, 2026 | veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30... |
| CVE-2026-54078 | HIGH | 8.7 | 0.3% | Jul 29, 2026 | veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve... |
| CVE-2026-16543 | HIGH | 7.1 | — | Jul 29, 2026 | Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation pr... |
| CVE-2026-16465 | HIGH | 7.1 | 0.1% | Jul 29, 2026 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabili... |
| CVE-2026-16463 | HIGH | 7.8 | 0.2% | Jul 29, 2026 | A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A m... |
| CVE-2026-15228 | HIGH | 7.1 | — | Jul 29, 2026 | Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clust... |
| CVE-2026-66723 | HIGH | 7 | 0.5% | Jul 29, 2026 | MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. ... |
| CVE-2026-65947 | HIGH | 7.3 | 0.1% | Jul 29, 2026 | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 |
| CVE-2026-65886 | HIGH | 7.5 | 0.4% | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unaut... |
| CVE-2026-59247 | HIGH | 7.6 | 0.1% | Jul 29, 2026 | Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute fo... |
| CVE-2026-54666 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch... |
| CVE-2026-54664 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch... |
| CVE-2026-54662 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-... |
| CVE-2026-54661 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templat... |
| CVE-2026-54660 | HIGH | 7.4 | 0.2% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol... |
| CVE-2026-12703 | HIGH | 8 | 0.2% | Jul 29, 2026 | TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti... |
| CVE-2026-67216 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now