2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61378 | MEDIUM | 6.8 | 0.1% | Jul 16, 2026 | A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to... |
| CVE-2026-60073 | MEDIUM | 5.9 | 0.2% | Jul 16, 2026 | An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB ... |
| CVE-2026-57896 | MEDIUM | 6.9 | 0.1% | Jul 16, 2026 | An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti... |
| CVE-2026-55173 | HIGH | 8.1 | 3.4% | Jul 16, 2026 | WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because ... |
| CVE-2026-53410 | HIGH | 7 | 0.1% | Jul 16, 2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl... |
| CVE-2026-53409 | HIGH | 7.8 | 0.2% | Jul 16, 2026 | Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct ... |
| CVE-2026-44023 | HIGH | 8.6 | 0.3% | Jul 16, 2026 | Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.... |
| CVE-2026-44019 | HIGH | 8.1 | 0.2% | Jul 16, 2026 | Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.... |
| CVE-2026-38158 | CRITICAL | 9.8 | 0.2% | Jul 16, 2026 | A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to acc... |
| CVE-2026-36425 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user... |
| CVE-2026-33731 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/Aut... |
| CVE-2026-33692 | HIGH | 7.5 | 0.5% | Jul 16, 2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through ... |
| CVE-2026-11889 | HIGH | 7.1 | 0.2% | Jul 16, 2026 | SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation at... |
| CVE-2026-63397 | HIGH | 7.1 | 0.3% | Jul 16, 2026 | remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed t... |
| CVE-2026-63089 | CRITICAL | 9.3 | 0.2% | Jul 16, 2026 | WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation... |
| CVE-2026-62994 | LOW | 3.7 | 0.3% | Jul 16, 2026 | CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreD... |
| CVE-2026-62963 | HIGH | 8.7 | 0.3% | Jul 16, 2026 | Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket tr... |
| CVE-2026-62309 | HIGH | 7.5 | 0.4% | Jul 16, 2026 | CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when... |
| CVE-2026-62299 | MEDIUM | 5.3 | 0.3% | Jul 16, 2026 | CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an ... |
| CVE-2026-62290 | HIGH | 7.3 | 0.1% | Jul 16, 2026 | cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc... |
| CVE-2026-61718 | MEDIUM | 5.4 | 0.3% | Jul 16, 2026 | bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb w... |
| CVE-2026-61389 | HIGH | 7.3 | 0.1% | Jul 16, 2026 | An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt... |
| CVE-2026-60140 | MEDIUM | 6.9 | 0.1% | Jul 16, 2026 | An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti... |
| CVE-2026-60063 | HIGH | 7.3 | 0.1% | Jul 16, 2026 | An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt... |
| CVE-2026-55629 | HIGH | 8.7 | 0.5% | Jul 16, 2026 | Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cg... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now