2026 CVE Vulnerabilities
56,898 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64878 | CRITICAL | 9.9 | 0.5% | Jul 21, 2026 | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting ... |
| CVE-2026-64617 | LOW | 3.8 | 0.2% | Jul 21, 2026 | Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL ... |
| CVE-2026-64616 | LOW | 3.3 | 0.2% | Jul 21, 2026 | Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL... |
| CVE-2026-64615 | LOW | 3.3 | 0.2% | Jul 21, 2026 | Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL o... |
| CVE-2026-64614 | LOW | 3.8 | 0.2% | Jul 21, 2026 | Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL o... |
| CVE-2026-64613 | MEDIUM | 6.2 | 0.2% | Jul 21, 2026 | Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOL... |
| CVE-2026-59147 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent i... |
| CVE-2026-59146 | HIGH | 7.8 | 0.2% | Jul 21, 2026 | Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, lin... |
| CVE-2026-59145 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena i... |
| CVE-2026-59144 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in rin... |
| CVE-2026-59143 | MEDIUM | 6.3 | 0.2% | Jul 21, 2026 | Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offse... |
| CVE-2026-56852 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. |
| CVE-2026-56146 | MEDIUM | 5.4 | 0.2% | Jul 21, 2026 | Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configur... |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.3% | Jul 21, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
| CVE-2026-56144 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl... |
| CVE-2026-50759 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instan... |
| CVE-2026-50758 | HIGH | 8.1 | 0.3% | Jul 21, 2026 | Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary c... |
| CVE-2026-50757 | HIGH | 7.8 | 0.4% | Jul 21, 2026 | Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary cod... |
| CVE-2026-50756 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-pro... |
| CVE-2026-50755 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwar... |
| CVE-2026-49092 | MEDIUM | 4.3 | 0.2% | Jul 21, 2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v... |
| CVE-2026-47671 | MEDIUM | 5.4 | 0.3% | Jul 21, 2026 | Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost c... |
| CVE-2026-47667 | HIGH | 7.5 | 0.4% | Jul 21, 2026 | CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field i... |
| CVE-2026-46600 | HIGH | 7.5 | 0.4% | Jul 21, 2026 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. |
| CVE-2026-46403 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithT... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now