2026 CVE Vulnerabilities
43,288 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10683 | MEDIUM | 4.6 | 0.1% | Jul 27, 2026 | In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handl... |
| CVE-2026-66030 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen... |
| CVE-2026-66029 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent... |
| CVE-2026-64645 | MEDIUM | 6.1 | 1.0% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64644 | MEDIUM | 5.3 | 0.5% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-64643 | MEDIUM | 5.3 | 0.7% | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr... |
| CVE-2026-54272 | MEDIUM | 6.9 | — | Jul 27, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2... |
| CVE-2026-48052 | MEDIUM | 5.4 | 0.2% | Jul 27, 2026 | Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i... |
| CVE-2026-17570 | MEDIUM | 4.3 | 0.2% | Jul 27, 2026 | Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg... |
| CVE-2026-17569 | MEDIUM | 4.3 | 0.2% | Jul 27, 2026 | Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per... |
| CVE-2026-66391 | MEDIUM | 6.5 | 0.2% | Jul 27, 2026 | Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Ap... |
| CVE-2026-66390 | MEDIUM | 6.1 | 0.2% | Jul 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th... |
| CVE-2026-17531 | MEDIUM | 5 | 0.2% | Jul 27, 2026 | A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality... |
| CVE-2026-47078 | MEDIUM | 4.8 | 0.2% | Jul 27, 2026 | Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extrac... |
| CVE-2026-17574 | MEDIUM | 5.2 | 0.1% | Jul 27, 2026 | HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an i... |
| CVE-2026-17573 | MEDIUM | 4 | 0.1% | Jul 27, 2026 | A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized c... |
| CVE-2026-17572 | MEDIUM | 5.5 | 0.1% | Jul 27, 2026 | Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows att... |
| CVE-2026-17530 | MEDIUM | 6.3 | — | Jul 27, 2026 | A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function ... |
| CVE-2026-17529 | MEDIUM | 6.3 | — | Jul 27, 2026 | A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/... |
| CVE-2026-66477 | MEDIUM | 5.3 | — | Jul 27, 2026 | Unauthenticated Broken Access Control in Gillion <= 4.13 versions. |
| CVE-2026-66476 | MEDIUM | 4.9 | — | Jul 27, 2026 | Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions. |
| CVE-2026-66475 | MEDIUM | 5.9 | — | Jul 27, 2026 | Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout Manager <= 3.0.5 versi... |
| CVE-2026-66474 | MEDIUM | 4.3 | — | Jul 27, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions. |
| CVE-2026-66448 | MEDIUM | 6.5 | — | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. |
| CVE-2026-66445 | MEDIUM | 6.5 | — | Jul 27, 2026 | Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now