2026 CVE Vulnerabilities
43,288 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43753 | MEDIUM | 4.6 | 0.2% | Jul 27, 2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO... |
| CVE-2026-43744 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.... |
| CVE-2026-43739 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.... |
| CVE-2026-43738 | MEDIUM | 5.5 | 0.2% | Jul 27, 2026 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8.... |
| CVE-2026-43714 | MEDIUM | 5.5 | 0.2% | Jul 27, 2026 | The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia... |
| CVE-2026-43665 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1... |
| CVE-2026-28932 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is f... |
| CVE-2026-28900 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma... |
| CVE-2026-28849 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A malici... |
| CVE-2026-20672 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.... |
| CVE-2026-12001 | MEDIUM | 5.2 | 0.2% | Jul 27, 2026 | A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-... |
| CVE-2026-66018 | MEDIUM | 6.5 | 0.2% | Jul 27, 2026 | Build readers can access another repository's environment properties. A caller with read access to an ordinary repositor... |
| CVE-2026-65925 | MEDIUM | 6.5 | 0.2% | Jul 27, 2026 | A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and ret... |
| CVE-2026-65924 | MEDIUM | 6.5 | 0.2% | Jul 27, 2026 | JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (... |
| CVE-2026-65923 | MEDIUM | 6.8 | 0.2% | Jul 27, 2026 | A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository... |
| CVE-2026-65922 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository acc... |
| CVE-2026-65618 | MEDIUM | 6.5 | 0.2% | Jul 27, 2026 | Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized ... |
| CVE-2026-64649 | MEDIUM | 6.5 | 0.6% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64648 | MEDIUM | 5.4 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-59729 | MEDIUM | 5.1 | 0.3% | Jul 27, 2026 | Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped sp... |
| CVE-2026-66757 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memor... |
| CVE-2026-66031 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent... |
| CVE-2026-64647 | MEDIUM | 5.4 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64646 | MEDIUM | 5.3 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-17612 | MEDIUM | 6.9 | — | Jul 27, 2026 | Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now