2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63175 | HIGH | 7.1 | 0.3% | Jul 15, 2026 | PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than in... |
| CVE-2026-62314 | MEDIUM | 5.8 | 0.3% | Jul 15, 2026 | Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap... |
| CVE-2026-55652 | CRITICAL | 9.8 | 0.4% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequest... |
| CVE-2026-55576 | HIGH | 8.8 | 0.3% | Jul 15, 2026 | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/r... |
| CVE-2026-55445 | CRITICAL | 9.3 | 0.4% | Jul 15, 2026 | Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the... |
| CVE-2026-55234 | HIGH | 8.5 | 0.2% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.j... |
| CVE-2026-54458 | CRITICAL | 9.6 | 0.3% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerabi... |
| CVE-2026-53447 | MEDIUM | 6.5 | 0.2% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js use... |
| CVE-2026-53446 | MEDIUM | 6.2 | 0.3% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js a... |
| CVE-2026-53445 | HIGH | 7.1 | 0.2% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publicatio... |
| CVE-2026-53444 | HIGH | 7.6 | 0.2% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/o... |
| CVE-2026-52893 | CRITICAL | 9.2 | 0.3% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/user... |
| CVE-2026-52892 | MEDIUM | 6.5 | 0.3% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use r... |
| CVE-2026-52891 | CRITICAL | 9.9 | 0.4% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied fil... |
| CVE-2026-52890 | HIGH | 7.1 | 0.3% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachm... |
| CVE-2026-50183 | MEDIUM | 4.7 | 0.2% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerabilit... |
| CVE-2026-50182 | MEDIUM | 6.1 | 0.2% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerabil... |
| CVE-2026-49279 | HIGH | 7.7 | 0.3% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the aut... |
| CVE-2026-48795 | HIGH | 8.6 | 0.5% | Jul 15, 2026 | AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompl... |
| CVE-2026-45313 | HIGH | 7.7 | 0.1% | Jul 15, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegist... |
| CVE-2026-38974 | MEDIUM | 5.3 | 0.1% | Jul 15, 2026 | Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. |
| CVE-2026-38755 | LOW | 2.9 | 0.3% | Jul 15, 2026 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Ser... |
| CVE-2026-38754 | MEDIUM | 5.1 | 0.2% | Jul 15, 2026 | A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv... |
| CVE-2026-38752 | LOW | 2.9 | 0.3% | Jul 15, 2026 | A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial ... |
| CVE-2026-36590 | HIGH | 7.5 | 0.3% | Jul 15, 2026 | An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now