2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45162 | HIGH | 8 | 0.6% | Jul 17, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc... |
| CVE-2026-16073 | LOW | 3.5 | 0.2% | Jul 17, 2026 | A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S... |
| CVE-2026-9762 | HIGH | 7.8 | 0.2% | Jul 17, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under u... |
| CVE-2026-9202 | CRITICAL | 9.8 | 0.3% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow... |
| CVE-2026-9198 | CRITICAL | 9.8 | 17.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER toke... |
| CVE-2026-50273 | HIGH | 7.5 | — | Jul 17, 2026 | Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing librarie... |
| CVE-2026-48016 | MEDIUM | 4.3 | 0.2% | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment... |
| CVE-2026-48015 | MEDIUM | 4.9 | — | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelis... |
| CVE-2026-48014 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action... |
| CVE-2026-48010 | MEDIUM | 6.5 | — | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framewo... |
| CVE-2026-48009 | MEDIUM | 6.8 | — | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:re... |
| CVE-2026-48008 | MEDIUM | 6.5 | — | Jul 17, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL... |
| CVE-2026-9588 | HIGH | 7 | — | Jul 17, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicem... |
| CVE-2026-9587 | HIGH | 7.1 | — | Jul 17, 2026 | An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file ... |
| CVE-2026-9586 | CRITICAL | 9.8 | 1.1% | Jul 17, 2026 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint pr... |
| CVE-2026-9585 | HIGH | 8.6 | — | Jul 17, 2026 | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.... |
| CVE-2026-8297 | CRITICAL | 9.8 | — | Jul 17, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics En... |
| CVE-2026-63309 | MEDIUM | 4.3 | — | Jul 17, 2026 | SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to... |
| CVE-2026-63308 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Helm through 4.2.3, fixed in commit ba6c9a2, contains a denial of service vulnerability in the Files.Lines template help... |
| CVE-2026-63307 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{i... |
| CVE-2026-63101 | HIGH | 8.7 | — | Jul 17, 2026 | Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers t... |
| CVE-2026-57860 | HIGH | 7.8 | — | Jul 17, 2026 | ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined i... |
| CVE-2026-54496 | CRITICAL | 9.3 | — | Jul 17, 2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primit... |
| CVE-2026-49216 | MEDIUM | 5.4 | 0.3% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/... |
| CVE-2026-49215 | MEDIUM | 5.4 | 0.2% | Jul 17, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventList... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now