2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66063 | MEDIUM | 6.5 | 0.2% | Jul 28, 2026 | goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.... |
| CVE-2026-59921 | MEDIUM | 6.5 | 0.5% | Jul 28, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ... |
| CVE-2026-54659 | MEDIUM | 6.9 | 0.4% | Jul 28, 2026 | Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18... |
| CVE-2026-59943 | MEDIUM | 5.3 | 0.3% | Jul 28, 2026 | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted con... |
| CVE-2026-56722 | MEDIUM | 5.3 | 0.6% | Jul 28, 2026 | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can byp... |
| CVE-2026-49447 | MEDIUM | 5.3 | 0.2% | Jul 28, 2026 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as ... |
| CVE-2026-16581 | MEDIUM | 6.9 | 0.2% | Jul 28, 2026 | In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulner... |
| CVE-2026-14515 | MEDIUM | 6.1 | 0.2% | Jul 28, 2026 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to conduct a cross-site scriptin... |
| CVE-2026-57511 | MEDIUM | 6.3 | 0.2% | Jul 28, 2026 | SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject... |
| CVE-2026-3158 | MEDIUM | 4.3 | 0.2% | Jul 28, 2026 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ... |
| CVE-2026-3157 | MEDIUM | 4.3 | 0.2% | Jul 28, 2026 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ... |
| CVE-2026-1918 | MEDIUM | 4.9 | 0.3% | Jul 28, 2026 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ... |
| CVE-2026-16192 | MEDIUM | 6.5 | 0.3% | Jul 28, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability wh... |
| CVE-2026-16107 | MEDIUM | 5.9 | 0.2% | Jul 28, 2026 | IBM TS4500 CLI tool Versions: 0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validat... |
| CVE-2026-11391 | MEDIUM | 6.3 | 0.2% | Jul 28, 2026 | Tanium addressed a SQL injection vulnerability in Patch. |
| CVE-2026-7362 | MEDIUM | 6.5 | 0.2% | Jul 28, 2026 | IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1... |
| CVE-2026-5114 | MEDIUM | 4.9 | 0.3% | Jul 28, 2026 | The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and ... |
| CVE-2026-50735 | MEDIUM | 6.1 | 0.2% | Jul 28, 2026 | pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol me... |
| CVE-2026-4932 | MEDIUM | 4.2 | — | Jul 28, 2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physica... |
| CVE-2026-4912 | MEDIUM | 4.1 | — | Jul 28, 2026 | The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio... |
| CVE-2026-48058 | MEDIUM | 4.6 | 0.2% | Jul 28, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern... |
| CVE-2026-47768 | MEDIUM | 5.5 | 0.1% | Jul 28, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-... |
| CVE-2026-47725 | MEDIUM | 6.9 | 0.2% | Jul 28, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every ... |
| CVE-2026-15304 | MEDIUM | 6.5 | — | Jul 28, 2026 | The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions ... |
| CVE-2026-48025 | MEDIUM | 6.9 | 0.3% | Jul 28, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, intern... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now