2026 CVE Vulnerabilities
56,949 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13445 | HIGH | 8.1 | 0.2% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an... |
| CVE-2026-8861 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error messag... |
| CVE-2026-8859 | CRITICAL | 9.9 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations ... |
| CVE-2026-8635 | CRITICAL | 9.9 | 0.3% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipul... |
| CVE-2026-8505 | CRITICAL | 9.8 | 0.6% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthentica... |
| CVE-2026-8481 | CRITICAL | 9.9 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API ... |
| CVE-2026-8476 | CRITICAL | 9.9 | 0.5% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching m... |
| CVE-2026-8056 | HIGH | 8.8 | 0.3% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API... |
| CVE-2026-7872 | HIGH | 8.1 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing... |
| CVE-2026-7771 | MEDIUM | 5.5 | 0.1% | Jul 17, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted stat... |
| CVE-2026-7755 | HIGH | 8.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcemen... |
| CVE-2026-7754 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure defa... |
| CVE-2026-7667 | HIGH | 8.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacke... |
| CVE-2026-7364 | MEDIUM | 6.1 | 0.3% | Jul 17, 2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident... |
| CVE-2026-63030 | CRITICAL | 9.8 | 38.6% | Jul 17, 2026 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which... |
| CVE-2026-60137 | MEDIUM | 5.9 | 78.0% | Jul 17, 2026 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in p... |
| CVE-2026-55254 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src... |
| CVE-2026-54465 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to im... |
| CVE-2026-54464 | MEDIUM | 6.3 | 0.4% | Jul 17, 2026 | ### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can ... |
| CVE-2026-54463 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket pro... |
| CVE-2026-54171 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip add... |
| CVE-2026-52199 | CRITICAL | 9.1 | 0.6% | Jul 17, 2026 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/... |
| CVE-2026-51833 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can ... |
| CVE-2026-50289 | HIGH | 8.8 | 1.1% | Jul 17, 2026 | systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is v... |
| CVE-2026-50197 | HIGH | 7.8 | 0.5% | Jul 17, 2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now