2026 CVE Vulnerabilities
43,288 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48374 | HIGH | 7.8 | 0.2% | Jul 28, 2026 | Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability th... |
| CVE-2026-47726 | HIGH | 7.1 | 0.2% | Jul 28, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern... |
| CVE-2026-18107 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insid... |
| CVE-2026-16771 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on ... |
| CVE-2026-16496 | HIGH | 8.9 | 0.3% | Jul 28, 2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful t... |
| CVE-2026-15992 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.... |
| CVE-2026-14869 | HIGH | 8.6 | 0.3% | Jul 28, 2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTT... |
| CVE-2026-59933 | HIGH | 7.5 | 0.7% | Jul 28, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t... |
| CVE-2026-59931 | HIGH | 7.7 | 0.5% | Jul 28, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t... |
| CVE-2026-54635 | HIGH | 7.5 | 0.4% | Jul 28, 2026 | pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.... |
| CVE-2026-48388 | HIGH | 8.6 | 0.2% | Jul 28, 2026 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in ... |
| CVE-2026-48372 | HIGH | 7.8 | 0.2% | Jul 28, 2026 | Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i... |
| CVE-2026-67185 | HIGH | 8.7 | 0.5% | Jul 28, 2026 | TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary fi... |
| CVE-2026-67184 | HIGH | 8.7 | 0.4% | Jul 28, 2026 | TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to ... |
| CVE-2026-67183 | HIGH | 8.7 | 0.4% | Jul 28, 2026 | TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available me... |
| CVE-2026-67182 | HIGH | 7.5 | 0.4% | Jul 28, 2026 | Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass acce... |
| CVE-2026-54609 | HIGH | 8.6 | 0.3% | Jul 28, 2026 | QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handle... |
| CVE-2026-54605 | HIGH | 7.2 | — | Jul 28, 2026 | OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth:... |
| CVE-2026-54603 | HIGH | 8.6 | — | Jul 28, 2026 | OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0... |
| CVE-2026-54345 | HIGH | 7.5 | 0.4% | Jul 28, 2026 | gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes... |
| CVE-2026-54332 | HIGH | 7.5 | 0.4% | Jul 28, 2026 | gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow dec... |
| CVE-2026-18084 | HIGH | 8.6 | 0.3% | Jul 28, 2026 | Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackB... |
| CVE-2026-16313 | HIGH | 7.6 | 0.2% | Jul 28, 2026 | A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification ... |
| CVE-2026-66754 | HIGH | 8.2 | 0.4% | Jul 28, 2026 | Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that all... |
| CVE-2026-66749 | HIGH | 7.1 | 0.3% | Jul 28, 2026 | Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now