2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44182 | CRITICAL | 10 | 0.3% | Jul 16, 2026 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber... |
| CVE-2026-44181 | CRITICAL | 10 | 0.5% | Jul 16, 2026 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber... |
| CVE-2026-43978 | HIGH | 8.1 | 0.2% | Jul 16, 2026 | wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their sess... |
| CVE-2026-43977 | HIGH | 7.5 | 0.2% | Jul 16, 2026 | wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth... |
| CVE-2026-15997 | LOW | 1.7 | 0.1% | Jul 16, 2026 | Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffer... |
| CVE-2026-14253 | — | — | — | Jul 16, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-11740 | — | — | — | Jul 16, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-62826 | MEDIUM | 5.4 | 0.2% | Jul 16, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-59117 | HIGH | 7.5 | 0.4% | Jul 16, 2026 | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. |
| CVE-2026-58643 | MEDIUM | 6.1 | 0.2% | Jul 16, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an u... |
| CVE-2026-58598 | HIGH | 7 | 0.2% | Jul 16, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all... |
| CVE-2026-57077 | HIGH | 7.7 | 0.2% | Jul 16, 2026 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In t... |
| CVE-2026-57076 | HIGH | 7.8 | 0.2% | Jul 16, 2026 | YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key i... |
| CVE-2026-57075 | CRITICAL | 9.1 | 0.2% | Jul 16, 2026 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64... |
| CVE-2026-53412 | CRITICAL | 9.8 | 0.6% | Jul 16, 2026 | Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind... |
| CVE-2026-53411 | HIGH | 7 | 0.1% | Jul 16, 2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl... |
| CVE-2026-45368 | HIGH | 8.4 | 0.3% | Jul 16, 2026 | Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for ... |
| CVE-2026-45334 | MEDIUM | 5.3 | 0.4% | Jul 16, 2026 | Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature ret... |
| CVE-2026-44180 | CRITICAL | 9.8 | 0.5% | Jul 16, 2026 | Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber... |
| CVE-2026-44177 | HIGH | 8.8 | 0.5% | Jul 16, 2026 | Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correct... |
| CVE-2026-44176 | MEDIUM | 6 | 0.2% | Jul 16, 2026 | Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` per... |
| CVE-2026-44175 | HIGH | 8.5 | 0.3% | Jul 16, 2026 | Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize... |
| CVE-2026-44174 | HIGH | 8.7 | 0.3% | Jul 16, 2026 | Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes... |
| CVE-2026-14782 | MEDIUM | 4.9 | 0.2% | Jul 16, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Cu... |
| CVE-2026-13713 | MEDIUM | 6.2 | 0.2% | Jul 16, 2026 | YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now