2026 CVE Vulnerabilities
43,288 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14996 | HIGH | 8.2 | 0.2% | Jul 28, 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management. |
| CVE-2026-14981 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 a... |
| CVE-2026-14959 | HIGH | 7.2 | 1.0% | Jul 28, 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to ... |
| CVE-2026-14958 | HIGH | 7.2 | 0.5% | Jul 28, 2026 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to ... |
| CVE-2026-14893 | HIGH | 7.3 | 0.3% | Jul 28, 2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core ... |
| CVE-2026-14528 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information. |
| CVE-2026-13463 | HIGH | 7.5 | 0.2% | Jul 28, 2026 | IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of creden... |
| CVE-2026-13442 | HIGH | 7.1 | 0.2% | Jul 28, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only... |
| CVE-2026-57510 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers t... |
| CVE-2026-55555 | HIGH | 7.5 | 0.5% | Jul 28, 2026 | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack thr... |
| CVE-2026-55554 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot bo... |
| CVE-2026-48060 | HIGH | 8.1 | 0.3% | Jul 28, 2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which... |
| CVE-2026-16347 | HIGH | 8.8 | 0.2% | Jul 28, 2026 | MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessi... |
| CVE-2026-7769 | HIGH | 8.1 | 0.3% | Jul 28, 2026 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ... |
| CVE-2026-66745 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability t... |
| CVE-2026-59932 | HIGH | 7.5 | 0.7% | Jul 28, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t... |
| CVE-2026-50738 | HIGH | 7.7 | 0.3% | Jul 28, 2026 | A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced aft... |
| CVE-2026-49258 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*... |
| CVE-2026-48396 | HIGH | 8.6 | 0.2% | Jul 28, 2026 | Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the cont... |
| CVE-2026-48395 | HIGH | 8.6 | 0.2% | Jul 28, 2026 | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex... |
| CVE-2026-48394 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ... |
| CVE-2026-48393 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ... |
| CVE-2026-48392 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ... |
| CVE-2026-48391 | HIGH | 8.2 | 0.2% | Jul 28, 2026 | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex... |
| CVE-2026-48390 | HIGH | 8.2 | 0.1% | Jul 28, 2026 | Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker co... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now