2026 CVE Vulnerabilities
56,949 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50163 | HIGH | 7.1 | 0.4% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 vali... |
| CVE-2026-50162 | MEDIUM | 6.9 | 0.5% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a le... |
| CVE-2026-50151 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completeP... |
| CVE-2026-4942 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Tran... |
| CVE-2026-4938 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident... |
| CVE-2026-49852 | HIGH | 8.7 | 0.2% | Jul 17, 2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2026-49834 | HIGH | 7.5 | 0.1% | Jul 17, 2026 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransp... |
| CVE-2026-49284 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSA... |
| CVE-2026-48978 | LOW | 2.1 | 0.3% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's ... |
| CVE-2026-48819 | MEDIUM | 4.8 | 0.4% | Jul 17, 2026 | Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/pa... |
| CVE-2026-48504 | MEDIUM | 5.3 | 0.4% | Jul 17, 2026 | OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_cont... |
| CVE-2026-48373 | HIGH | 7.8 | 0.3% | Jul 17, 2026 | Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i... |
| CVE-2026-46420 | CRITICAL | 9.8 | 1.1% | Jul 17, 2026 | setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.2... |
| CVE-2026-45799 | HIGH | 7.5 | 0.5% | Jul 17, 2026 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArra... |
| CVE-2026-45704 | HIGH | 7.1 | 0.3% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses i... |
| CVE-2026-45260 | HIGH | 8.1 | 0.4% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV ass... |
| CVE-2026-44974 | HIGH | 7.7 | 0.3% | Jul 17, 2026 | @hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrenc... |
| CVE-2026-44739 | HIGH | 8.7 | 0.3% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigActi... |
| CVE-2026-43636 | — | — | — | Jul 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-42168 | CRITICAL | 9.1 | 1.2% | Jul 17, 2026 | django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner ... |
| CVE-2026-36669 | CRITICAL | 9.8 | 0.6% | Jul 17, 2026 | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote ... |
| CVE-2026-16118 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the ... |
| CVE-2026-15995 | MEDIUM | 4.2 | 0.1% | Jul 17, 2026 | IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain inc... |
| CVE-2026-15415 | MEDIUM | 6.8 | 0.2% | Jul 17, 2026 | AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure ... |
| CVE-2026-15322 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now