2026 CVE Vulnerabilities
56,994 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15696 | HIGH | 8.8 | — | Jul 14, 2026 | A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the... |
| CVE-2026-15695 | HIGH | 8.8 | 0.8% | Jul 14, 2026 | A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file... |
| CVE-2026-15694 | HIGH | 8.8 | — | Jul 14, 2026 | A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/S... |
| CVE-2026-15265 | CRITICAL | 9.1 | 0.6% | Jul 14, 2026 | A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitr... |
| CVE-2026-14903 | MEDIUM | 6.5 | 1.0% | Jul 14, 2026 | Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary fil... |
| CVE-2026-14902 | MEDIUM | 6.1 | 0.5% | Jul 14, 2026 | An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users ... |
| CVE-2026-10714 | HIGH | 8.8 | — | Jul 14, 2026 | A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature valid... |
| CVE-2026-10672 | CRITICAL | 9.1 | 0.4% | Jul 14, 2026 | subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri... |
| CVE-2026-10671 | HIGH | 7.1 | 0.1% | Jul 14, 2026 | In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used K_SYSC... |
| CVE-2026-10670 | MEDIUM | 5.5 | 0.1% | Jul 14, 2026 | The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kerne... |
| CVE-2026-10669 | HIGH | 7.8 | 0.1% | Jul 14, 2026 | On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the... |
| CVE-2026-10573 | MEDIUM | 6.3 | 0.4% | Jul 14, 2026 | A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of ... |
| CVE-2026-53566 | MEDIUM | 6.8 | 0.1% | Jul 14, 2026 | Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Ac... |
| CVE-2026-15693 | HIGH | 8.8 | — | Jul 14, 2026 | A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFil... |
| CVE-2026-8314 | HIGH | 7.3 | — | Jul 14, 2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) compo... |
| CVE-2026-8313 | HIGH | 7.3 | — | Jul 14, 2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) comp... |
| CVE-2026-8312 | HIGH | 7.3 | — | Jul 14, 2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) compo... |
| CVE-2026-8085 | HIGH | 7.3 | — | Jul 14, 2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) compo... |
| CVE-2026-62393 | MEDIUM | 4.3 | 0.5% | Jul 14, 2026 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job... |
| CVE-2026-62392 | CRITICAL | 9.8 | — | Jul 14, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin... |
| CVE-2026-62390 | CRITICAL | 9.8 | — | Jul 14, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A ba... |
| CVE-2026-53565 | HIGH | 8.5 | 0.1% | Jul 14, 2026 | Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis ... |
| CVE-2026-49488 | MEDIUM | 6.5 | 0.7% | Jul 14, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. Th... |
| CVE-2026-15719 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.... |
| CVE-2026-15718 | MEDIUM | 4.3 | 0.2% | Jul 14, 2026 | We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now