2026 CVE Vulnerabilities
55,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7120 | MEDIUM | 5.3 | 0.2% | Jul 23, 2026 | @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the ... |
| CVE-2026-15074 | HIGH | 7.5 | 0.5% | Jul 23, 2026 | @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the... |
| CVE-2026-21723 | MEDIUM | 5.3 | 0.3% | Jul 23, 2026 | The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates ... |
| CVE-2026-16653 | MEDIUM | 5.5 | 0.7% | Jul 23, 2026 | A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the ... |
| CVE-2026-16632 | HIGH | 7.3 | 0.5% | Jul 23, 2026 | A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib... |
| CVE-2026-16631 | MEDIUM | 5.3 | 1.1% | Jul 23, 2026 | A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/p... |
| CVE-2026-61246 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60455 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60439 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60373 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60372 | CRITICAL | 9.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60371 | HIGH | 8 | 0.1% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60370 | HIGH | 7.5 | 0.2% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60369 | CRITICAL | 9.9 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60368 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60367 | CRITICAL | 9.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60366 | CRITICAL | 10 | 0.5% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-38766 | HIGH | 7.8 | 0.2% | Jul 22, 2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_1... |
| CVE-2026-38765 | HIGH | 7.8 | 0.2% | Jul 22, 2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne... |
| CVE-2026-38763 | MEDIUM | 5.5 | 0.2% | Jul 22, 2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the... |
| CVE-2026-16630 | MEDIUM | 5.3 | 1.1% | Jul 22, 2026 | A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the funct... |
| CVE-2026-16629 | MEDIUM | 5.3 | 0.6% | Jul 22, 2026 | A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the ... |
| CVE-2026-16628 | MEDIUM | 5.3 | 1.1% | Jul 22, 2026 | A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec o... |
| CVE-2026-64798 | CRITICAL | 9.1 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also... |
| CVE-2026-64797 | HIGH | 7.5 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now