2026 CVE Vulnerabilities
43,288 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12144 | HIGH | 8.8 | 0.4% | Jul 29, 2026 | The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl... |
| CVE-2026-56822 | HIGH | 7.4 | 0.1% | Jul 29, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ... |
| CVE-2026-56821 | HIGH | 7.4 | 0.1% | Jul 29, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ... |
| CVE-2026-54719 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.... |
| CVE-2026-54650 | HIGH | 8.6 | 0.4% | Jul 28, 2026 | openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publ... |
| CVE-2026-54638 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted... |
| CVE-2026-47219 | HIGH | 7.5 | 0.5% | Jul 28, 2026 | find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and w... |
| CVE-2026-55415 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch... |
| CVE-2026-55391 | HIGH | 7.5 | 0.2% | Jul 28, 2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch... |
| CVE-2026-55390 | HIGH | 7.5 | 0.4% | Jul 28, 2026 | datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema pars... |
| CVE-2026-55389 | HIGH | 7.5 | 0.4% | Jul 28, 2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch... |
| CVE-2026-54691 | HIGH | 8.2 | 0.2% | Jul 28, 2026 | datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_co... |
| CVE-2026-54690 | HIGH | 8.2 | 0.2% | Jul 28, 2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch... |
| CVE-2026-54656 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch... |
| CVE-2026-54655 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type v... |
| CVE-2026-54654 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-tem... |
| CVE-2026-54653 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch... |
| CVE-2026-54621 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union descriptio... |
| CVE-2026-59942 | HIGH | 7.5 | 0.4% | Jul 28, 2026 | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack v... |
| CVE-2026-59941 | HIGH | 7.5 | 0.5% | Jul 28, 2026 | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PN... |
| CVE-2026-15328 | HIGH | 8.1 | 0.2% | Jul 28, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i... |
| CVE-2026-15325 | HIGH | 8.7 | 0.2% | Jul 28, 2026 | IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling ... |
| CVE-2026-15280 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segm... |
| CVE-2026-15064 | HIGH | 8.7 | 0.2% | Jul 28, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i... |
| CVE-2026-15057 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now