2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46377 | MEDIUM | 6.2 | 0.1% | Jul 16, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1... |
| CVE-2026-46353 | HIGH | 8.1 | 0.3% | Jul 16, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a... |
| CVE-2026-46351 | HIGH | 8.1 | 0.3% | Jul 16, 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values wit... |
| CVE-2026-46338 | MEDIUM | 4.3 | 0.3% | Jul 16, 2026 | PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.... |
| CVE-2026-46687 | HIGH | 7.7 | 0.3% | Jul 16, 2026 | Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-t... |
| CVE-2026-46686 | HIGH | 8.5 | 0.3% | Jul 16, 2026 | Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword p... |
| CVE-2026-46341 | MEDIUM | 6.1 | 0.2% | Jul 16, 2026 | The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation... |
| CVE-2026-46336 | HIGH | 7.1 | 0.3% | Jul 16, 2026 | Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ... |
| CVE-2026-45336 | CRITICAL | 10 | 0.4% | Jul 16, 2026 | HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring ... |
| CVE-2026-44970 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_call... |
| CVE-2026-44969 | LOW | 3.3 | 0.1% | Jul 16, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/... |
| CVE-2026-44968 | MEDIUM | 6.3 | 0.1% | Jul 16, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/... |
| CVE-2026-15945 | LOW | 2.7 | 0.2% | Jul 16, 2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin ... |
| CVE-2026-15737 | MEDIUM | 5.7 | 0.2% | Jul 16, 2026 | AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on t... |
| CVE-2026-9046 | HIGH | 7.3 | — | Jul 16, 2026 | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications... |
| CVE-2026-6511 | MEDIUM | 6.8 | — | Jul 16, 2026 | During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart... |
| CVE-2026-63088 | HIGH | 8.6 | — | Jul 16, 2026 | stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-... |
| CVE-2026-63087 | CRITICAL | 9.8 | 0.4% | Jul 16, 2026 | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a... |
| CVE-2026-63086 | HIGH | 8.6 | — | Jul 16, 2026 | text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat... |
| CVE-2026-63085 | HIGH | 8.8 | 0.4% | Jul 16, 2026 | Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticate... |
| CVE-2026-57074 | CRITICAL | 9.1 | 0.2% | Jul 16, 2026 | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to ... |
| CVE-2026-57073 | CRITICAL | 9.1 | — | Jul 16, 2026 | HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to... |
| CVE-2026-55548 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/sr... |
| CVE-2026-55407 | MEDIUM | 6.3 | — | Jul 16, 2026 | Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the dec... |
| CVE-2026-55406 | MEDIUM | 5.9 | — | Jul 16, 2026 | Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a sound... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now