2026 CVE Vulnerabilities
56,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40553 | HIGH | 7.5 | — | Jul 13, 2026 | Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue... |
| CVE-2026-40469 | CRITICAL | 9.1 | — | Jul 13, 2026 | Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could b... |
| CVE-2026-40468 | CRITICAL | 9.1 | — | Jul 13, 2026 | Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaust... |
| CVE-2026-40467 | HIGH | 7.5 | — | Jul 13, 2026 | Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may ... |
| CVE-2026-15584 | HIGH | 7.5 | 0.2% | Jul 13, 2026 | A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged d... |
| CVE-2026-15559 | MEDIUM | 6.3 | — | Jul 13, 2026 | A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the... |
| CVE-2026-62147 | MEDIUM | 6.5 | — | Jul 13, 2026 | The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API respons... |
| CVE-2026-15558 | MEDIUM | 6.3 | — | Jul 13, 2026 | A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issu... |
| CVE-2026-12257 | CRITICAL | 9.3 | — | Jul 13, 2026 | Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located... |
| CVE-2026-9824 | MEDIUM | 4.3 | — | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels per... |
| CVE-2026-9820 | LOW | 3.8 | — | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams end... |
| CVE-2026-6541 | MEDIUM | 4.3 | — | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration change... |
| CVE-2026-4765 | NONE | 0 | 0.4% | Jul 13, 2026 | Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in t... |
| CVE-2026-14934 | CRITICAL | 9.4 | — | Jul 13, 2026 | A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Co... |
| CVE-2026-61985 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl... |
| CVE-2026-61983 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc... |
| CVE-2026-61977 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-sea... |
| CVE-2026-61976 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Ele... |
| CVE-2026-61975 | MEDIUM | 5.3 | 0.3% | Jul 13, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-re... |
| CVE-2026-61971 | LOW | 2.7 | 0.3% | Jul 13, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-pictu... |
| CVE-2026-61970 | MEDIUM | 4.9 | 0.2% | Jul 13, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbn... |
| CVE-2026-61968 | MEDIUM | 5.4 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-61958 | MEDIUM | 5.4 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows... |
| CVE-2026-61956 | HIGH | 7.1 | 0.2% | Jul 13, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allo... |
| CVE-2026-61955 | HIGH | 7.6 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now