2026 CVE Vulnerabilities
43,308 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64211 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: srcu: Don't queue workqueue handlers to never-onlin... |
| CVE-2026-8308 | MEDIUM | 6.1 | — | Jul 24, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Softwa... |
| CVE-2026-7007 | MEDIUM | 4.6 | 0.2% | Jul 24, 2026 | The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.... |
| CVE-2026-66007 | MEDIUM | 6.9 | 0.5% | Jul 24, 2026 | Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder... |
| CVE-2026-66006 | MEDIUM | 6.9 | 0.3% | Jul 24, 2026 | lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs... |
| CVE-2026-66005 | MEDIUM | 6.3 | 0.2% | Jul 24, 2026 | Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that ... |
| CVE-2026-66004 | MEDIUM | 6 | 0.3% | Jul 24, 2026 | BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all... |
| CVE-2026-55731 | MEDIUM | 6.6 | 0.3% | Jul 24, 2026 | Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI... |
| CVE-2026-49326 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest... |
| CVE-2026-17059 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloa... |
| CVE-2026-16802 | MEDIUM | 6.5 | 0.1% | Jul 24, 2026 | Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear... |
| CVE-2026-16799 | MEDIUM | 5 | 0.2% | Jul 24, 2026 | Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and ... |
| CVE-2026-16798 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.... |
| CVE-2026-17048 | MEDIUM | 4.9 | 0.2% | Jul 24, 2026 | A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs w... |
| CVE-2026-7484 | MEDIUM | 5.3 | — | Jul 24, 2026 | External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Fu... |
| CVE-2026-66010 | MEDIUM | 6.1 | 0.2% | Jul 24, 2026 | DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDL... |
| CVE-2026-66009 | MEDIUM | 6.3 | 0.3% | Jul 24, 2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages... |
| CVE-2026-66008 | MEDIUM | 6.3 | 0.3% | Jul 24, 2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target cla... |
| CVE-2026-46452 | MEDIUM | 5.3 | — | Jul 24, 2026 | Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken dat... |
| CVE-2026-45812 | MEDIUM | 6.5 | — | Jul 24, 2026 | Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event.... |
| CVE-2026-16743 | MEDIUM | 5.5 | — | Jul 24, 2026 | A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root ... |
| CVE-2026-16730 | MEDIUM | 5.5 | — | Jul 24, 2026 | A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer set... |
| CVE-2026-15663 | MEDIUM | 4.9 | 0.5% | Jul 24, 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injecti... |
| CVE-2026-63317 | MEDIUM | 5.6 | 0.3% | Jul 24, 2026 | Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected:... |
| CVE-2026-56391 | MEDIUM | 4.6 | 0.1% | Jul 24, 2026 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--ch... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now