2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50012 | MEDIUM | 5.5 | 2.3% | Jul 16, 2026 | Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handli... |
| CVE-2026-47751 | MEDIUM | 5.3 | 0.4% | Jul 16, 2026 | Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to... |
| CVE-2026-47729 | MEDIUM | 6.5 | 1.9% | Jul 16, 2026 | Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in t... |
| CVE-2026-46621 | CRITICAL | 9.1 | 0.7% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamica... |
| CVE-2026-46562 | CRITICAL | 9.8 | 0.6% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScrip... |
| CVE-2026-45795 | MEDIUM | 5.3 | — | Jul 16, 2026 | The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server ac... |
| CVE-2026-45612 | MEDIUM | 5.5 | — | Jul 16, 2026 | rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can... |
| CVE-2026-45576 | HIGH | 7.5 | 0.4% | Jul 16, 2026 | zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores at... |
| CVE-2026-45568 | CRITICAL | 9.1 | 0.4% | Jul 16, 2026 | zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Fl... |
| CVE-2026-45367 | HIGH | 7.5 | 0.5% | Jul 16, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7,... |
| CVE-2026-45325 | HIGH | 8.2 | 0.3% | Jul 16, 2026 | Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade... |
| CVE-2026-44632 | CRITICAL | 9.1 | 0.9% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs a... |
| CVE-2026-44596 | CRITICAL | 9.8 | 1.4% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handl... |
| CVE-2026-44595 | MEDIUM | 4.3 | 1.0% | Jul 16, 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGrou... |
| CVE-2026-3031 | CRITICAL | 9.8 | 0.2% | Jul 16, 2026 | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg... |
| CVE-2026-14371 | HIGH | 8.8 | — | Jul 16, 2026 | The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vul... |
| CVE-2026-13401 | HIGH | 7.5 | — | Jul 16, 2026 | XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_p... |
| CVE-2026-13397 | HIGH | 7.5 | 0.2% | Jul 16, 2026 | HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_... |
| CVE-2026-13104 | HIGH | 7.3 | — | Jul 16, 2026 | A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could al... |
| CVE-2026-13103 | HIGH | 7.3 | — | Jul 16, 2026 | A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market... |
| CVE-2026-10590 | MEDIUM | 6.7 | — | Jul 16, 2026 | A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrar... |
| CVE-2026-10589 | MEDIUM | 6.8 | — | Jul 16, 2026 | A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Manageme... |
| CVE-2026-10588 | MEDIUM | 6.7 | — | Jul 16, 2026 | A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management... |
| CVE-2026-10587 | MEDIUM | 6.8 | — | Jul 16, 2026 | A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management setting... |
| CVE-2026-63082 | MEDIUM | 5.4 | — | Jul 16, 2026 | Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now