2026 CVE Vulnerabilities
43,311 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64795 | MEDIUM | 5.4 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provide... |
| CVE-2026-64794 | MEDIUM | 6.5 | 0.2% | Jul 22, 2026 | Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - ... |
| CVE-2026-63281 | MEDIUM | 4.8 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values coul... |
| CVE-2026-13074 | MEDIUM | 6.9 | 0.4% | Jul 22, 2026 | An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combinati... |
| CVE-2026-13073 | MEDIUM | 5.3 | 0.4% | Jul 22, 2026 | An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte... |
| CVE-2026-13070 | MEDIUM | 6 | 0.1% | Jul 22, 2026 | A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons... |
| CVE-2026-13068 | MEDIUM | 4.3 | 0.1% | Jul 22, 2026 | An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate ac... |
| CVE-2026-13063 | MEDIUM | 5.3 | 0.4% | Jul 22, 2026 | An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem... |
| CVE-2026-13061 | MEDIUM | 5.3 | 0.2% | Jul 22, 2026 | An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi... |
| CVE-2026-13058 | MEDIUM | 6.5 | 0.2% | Jul 22, 2026 | An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf... |
| CVE-2026-13057 | MEDIUM | 6.5 | 0.3% | Jul 22, 2026 | An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In... |
| CVE-2026-3482 | MEDIUM | 5.3 | 0.3% | Jul 22, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.... |
| CVE-2026-65650 | MEDIUM | 4.3 | — | Jul 22, 2026 | Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. |
| CVE-2026-7328 | MEDIUM | 6.8 | — | Jul 22, 2026 | Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CM... |
| CVE-2026-65012 | MEDIUM | 6.3 | 0.4% | Jul 22, 2026 | InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_fo... |
| CVE-2026-65011 | MEDIUM | 5.3 | 0.4% | Jul 22, 2026 | Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de... |
| CVE-2026-16615 | MEDIUM | 6.8 | 0.3% | Jul 22, 2026 | A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, ... |
| CVE-2026-64828 | MEDIUM | 6.1 | 0.2% | Jul 22, 2026 | Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attac... |
| CVE-2026-44276 | MEDIUM | 4.4 | 0.1% | Jul 22, 2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauth... |
| CVE-2026-10822 | MEDIUM | 6.5 | — | Jul 22, 2026 | If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequ... |
| CVE-2026-10723 | MEDIUM | 6.8 | — | Jul 22, 2026 | BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMA... |
| CVE-2026-56444 | MEDIUM | 5.9 | 0.4% | Jul 22, 2026 | In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve... |
| CVE-2026-56416 | MEDIUM | 4.8 | 0.1% | Jul 22, 2026 | In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSI... |
| CVE-2026-55991 | MEDIUM | 5.9 | 0.2% | Jul 22, 2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 asserti... |
| CVE-2026-55990 | MEDIUM | 5.9 | 0.2% | Jul 22, 2026 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:'... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now