2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54728 | MEDIUM | 6.1 | 0.2% | Jul 16, 2026 | bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb ... |
| CVE-2026-49998 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verif... |
| CVE-2026-44982 | HIGH | 7.2 | 0.2% | Jul 16, 2026 | CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRe... |
| CVE-2026-44981 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/... |
| CVE-2026-15449 | MEDIUM | 5.8 | 0.1% | Jul 16, 2026 | A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC... |
| CVE-2026-15422 | CRITICAL | 9.1 | 0.5% | Jul 16, 2026 | The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address ... |
| CVE-2026-15352 | HIGH | 8.2 | 0.4% | Jul 16, 2026 | A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the a... |
| CVE-2026-54526 | CRITICAL | 9.9 | 0.2% | Jul 16, 2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t... |
| CVE-2026-53536 | MEDIUM | 5.3 | 0.2% | Jul 16, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endp... |
| CVE-2026-53535 | MEDIUM | 5.9 | 0.6% | Jul 16, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf... |
| CVE-2026-47089 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces... |
| CVE-2026-47088 | LOW | 3.1 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi... |
| CVE-2026-47087 | LOW | 3.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A... |
| CVE-2026-47086 | LOW | 3.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe... |
| CVE-2026-47085 | MEDIUM | 4 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk... |
| CVE-2026-47084 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An aut... |
| CVE-2026-47083 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u... |
| CVE-2026-47082 | MEDIUM | 5.4 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-ma... |
| CVE-2026-47081 | LOW | 3.1 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac... |
| CVE-2026-46515 | CRITICAL | 9.3 | 0.3% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call ... |
| CVE-2026-46514 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword... |
| CVE-2026-46513 | HIGH | 7.4 | 0.3% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by T... |
| CVE-2026-46512 | CRITICAL | 9.9 | 0.4% | Jul 16, 2026 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template para... |
| CVE-2026-46404 | MEDIUM | 6.8 | 0.3% | Jul 16, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly res... |
| CVE-2026-46378 | MEDIUM | 6.2 | 0.1% | Jul 16, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now