2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63081 | MEDIUM | 5.4 | 0.1% | Jul 16, 2026 | Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability ... |
| CVE-2026-59867 | HIGH | 7.1 | 1.9% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by ... |
| CVE-2026-59866 | CRITICAL | 9.3 | 1.4% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientCl... |
| CVE-2026-59865 | CRITICAL | 9.3 | 3.2% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.lang... |
| CVE-2026-59864 | CRITICAL | 9.3 | 1.3% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin g... |
| CVE-2026-57206 | HIGH | 8.6 | — | Jul 16, 2026 | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions... |
| CVE-2026-57205 | MEDIUM | 4.3 | — | Jul 16, 2026 | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions... |
| CVE-2026-55440 | MEDIUM | 6.5 | — | Jul 16, 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND... |
| CVE-2026-54733 | CRITICAL | 9.3 | — | Jul 16, 2026 | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration fo... |
| CVE-2026-54568 | MEDIUM | 4.3 | — | Jul 16, 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c... |
| CVE-2026-53598 | HIGH | 7.5 | 1.1% | Jul 16, 2026 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...... |
| CVE-2026-53597 | HIGH | 8.7 | 0.9% | Jul 16, 2026 | Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core T... |
| CVE-2026-45695 | CRITICAL | 9.8 | — | Jul 16, 2026 | Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-en... |
| CVE-2026-14890 | CRITICAL | 9.1 | 0.9% | Jul 16, 2026 | SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that d... |
| CVE-2026-12379 | MEDIUM | 6.8 | — | Jul 16, 2026 | An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard... |
| CVE-2026-59863 | HIGH | 7 | 1.1% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/worksp... |
| CVE-2026-59862 | HIGH | 7.5 | 1.0% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-... |
| CVE-2026-59861 | HIGH | 7.5 | 1.5% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAP... |
| CVE-2026-59860 | HIGH | 8.7 | 1.0% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation... |
| CVE-2026-59859 | HIGH | 8.7 | 1.0% | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI... |
| CVE-2026-59237 | MEDIUM | 6.9 | — | Jul 16, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Pro... |
| CVE-2026-14254 | HIGH | 8.3 | — | Jul 16, 2026 | A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed... |
| CVE-2026-5674 | HIGH | 8.8 | 0.2% | Jul 16, 2026 | A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed application... |
| CVE-2026-56456 | MEDIUM | 5.3 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently ... |
| CVE-2026-56455 | HIGH | 7.5 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The applicat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now