2026 CVE Vulnerabilities
56,979 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45804 | HIGH | 7.5 | 0.3% | Jul 15, 2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretraine... |
| CVE-2026-45793 | HIGH | 7.5 | — | Jul 15, 2026 | Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConf... |
| CVE-2026-20187 | HIGH | 7.5 | 0.3% | Jul 15, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c... |
| CVE-2026-20158 | HIGH | 7.5 | 0.3% | Jul 15, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c... |
| CVE-2026-20157 | CRITICAL | 9.8 | 0.1% | Jul 15, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c... |
| CVE-2026-20156 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c... |
| CVE-2026-20153 | HIGH | 7.5 | 0.3% | Jul 15, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c... |
| CVE-2026-20150 | HIGH | 8.8 | 0.2% | Jul 15, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c... |
| CVE-2026-20146 | MEDIUM | 5.5 | 0.5% | Jul 15, 2026 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a... |
| CVE-2026-1563 | MEDIUM | 4.8 | 0.3% | Jul 15, 2026 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a u... |
| CVE-2026-1562 | MEDIUM | 4.8 | 0.3% | Jul 15, 2026 | Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user... |
| CVE-2026-9007 | MEDIUM | 5.5 | — | Jul 15, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL... |
| CVE-2026-62843 | MEDIUM | 6.8 | — | Jul 15, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-62685 | HIGH | 8.1 | 0.3% | Jul 15, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-62683 | LOW | 3.1 | — | Jul 15, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-61828 | HIGH | 8.5 | — | Jul 15, 2026 | Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and ... |
| CVE-2026-61605 | — | — | — | Jul 15, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-58655. Reason: This candidate is a ... |
| CVE-2026-61371 | HIGH | 7.5 | — | Jul 15, 2026 | Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/... |
| CVE-2026-60005 | HIGH | 8.2 | 0.7% | Jul 15, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and ... |
| CVE-2026-55242 | HIGH | 8.8 | — | Jul 15, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated use... |
| CVE-2026-50148 | CRITICAL | 9.1 | 0.4% | Jul 15, 2026 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.2... |
| CVE-2026-50147 | HIGH | 7.6 | 0.2% | Jul 15, 2026 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.... |
| CVE-2026-47164 | HIGH | 7.7 | — | Jul 15, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the ... |
| CVE-2026-47160 | MEDIUM | 5.8 | — | Jul 15, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png en... |
| CVE-2026-47159 | MEDIUM | 6.9 | — | Jul 15, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-valid... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now