2026 CVE Vulnerabilities
56,979 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47158 | HIGH | 8.3 | — | Jul 15, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did ... |
| CVE-2026-46709 | HIGH | 7.8 | 0.2% | Jul 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths... |
| CVE-2026-45806 | HIGH | 7.7 | 0.4% | Jul 15, 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import pa... |
| CVE-2026-45805 | HIGH | 8.8 | — | Jul 15, 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/serve... |
| CVE-2026-45150 | MEDIUM | 6.3 | — | Jul 15, 2026 | Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security no... |
| CVE-2026-44986 | CRITICAL | 9.9 | — | Jul 15, 2026 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitation... |
| CVE-2026-41580 | MEDIUM | 6.1 | 0.2% | Jul 15, 2026 | Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirl... |
| CVE-2026-62294 | MEDIUM | 5.1 | — | Jul 15, 2026 | Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to... |
| CVE-2026-61836 | HIGH | 8.6 | 0.3% | Jul 15, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching ... |
| CVE-2026-61835 | HIGH | 7.7 | 0.3% | Jul 15, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on... |
| CVE-2026-61740 | CRITICAL | 9.3 | — | Jul 15, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRA... |
| CVE-2026-61736 | CRITICAL | 9.3 | — | Jul 15, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* ... |
| CVE-2026-61684 | HIGH | 8.8 | — | Jul 15, 2026 | FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints unde... |
| CVE-2026-61646 | MEDIUM | 6.3 | — | Jul 15, 2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only ... |
| CVE-2026-61644 | HIGH | 7.7 | — | Jul 15, 2026 | FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/ge... |
| CVE-2026-61613 | HIGH | 7.7 | 0.4% | Jul 15, 2026 | Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Curso... |
| CVE-2026-60065 | MEDIUM | 5.3 | 0.3% | Jul 15, 2026 | When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filte... |
| CVE-2026-60062 | MEDIUM | 6.4 | 0.2% | Jul 15, 2026 | The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files ou... |
| CVE-2026-59762 | HIGH | 8.7 | 0.5% | Jul 15, 2026 | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource ... |
| CVE-2026-56434 | HIGH | 8.3 | 0.4% | Jul 15, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist wh... |
| CVE-2026-55723 | HIGH | 8.7 | 0.3% | Jul 15, 2026 | When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection... |
| CVE-2026-54563 | HIGH | 7.1 | — | Jul 15, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a c... |
| CVE-2026-54562 | MEDIUM | 6.5 | — | Jul 15, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow acc... |
| CVE-2026-54560 | HIGH | 7.6 | — | Jul 15, 2026 | Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens... |
| CVE-2026-52865 | HIGH | 7.1 | 0.3% | Jul 15, 2026 | When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with per... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now