2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15093 | MEDIUM | 4.3 | 0.2% | Jul 17, 2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due... |
| CVE-2026-15091 | CRITICAL | 9.3 | 0.3% | Jul 17, 2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to imprope... |
| CVE-2026-15069 | MEDIUM | 5.4 | 0.2% | Jul 17, 2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to imp... |
| CVE-2026-14979 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ... |
| CVE-2026-14971 | HIGH | 7 | 0.1% | Jul 17, 2026 | IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attac... |
| CVE-2026-14501 | CRITICAL | 9.8 | 0.2% | Jul 17, 2026 | IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain se... |
| CVE-2026-14499 | HIGH | 8.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elev... |
| CVE-2026-13473 | CRITICAL | 9.8 | 0.5% | Jul 17, 2026 | IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner... |
| CVE-2026-13448 | CRITICAL | 9.8 | 0.5% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the... |
| CVE-2026-12283 | MEDIUM | 6.8 | 0.4% | Jul 17, 2026 | Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard... |
| CVE-2026-9171 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused ... |
| CVE-2026-9135 | CRITICAL | 9.9 | 0.8% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) co... |
| CVE-2026-9103 | CRITICAL | 9.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authenti... |
| CVE-2026-58195 | HIGH | 8.8 | 0.5% | Jul 17, 2026 | Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone... |
| CVE-2026-53712 | HIGH | 8.2 | 0.3% | Jul 17, 2026 | SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L... |
| CVE-2026-52746 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toM... |
| CVE-2026-50185 | LOW | 3.3 | 0.1% | Jul 17, 2026 | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-... |
| CVE-2026-49835 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middle... |
| CVE-2026-48487 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string a... |
| CVE-2026-48045 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_que... |
| CVE-2026-47184 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inser... |
| CVE-2026-47183 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exceptio... |
| CVE-2026-47180 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_label... |
| CVE-2026-45703 | MEDIUM | 6.4 | 0.2% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport expor... |
| CVE-2026-45309 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now