2026 CVE Vulnerabilities
43,380 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63280 | HIGH | 8.8 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manage... |
| CVE-2026-63265 | HIGH | 8 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension... |
| CVE-2026-13089 | HIGH | 7.5 | 0.2% | Jul 22, 2026 | OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorith... |
| CVE-2026-9737 | HIGH | 7.1 | 0.4% | Jul 22, 2026 | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the m... |
| CVE-2026-14899 | HIGH | 7.5 | 0.3% | Jul 22, 2026 | The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) ha... |
| CVE-2026-14881 | HIGH | 8.4 | 0.2% | Jul 22, 2026 | When importing connections in Compass it is possible to override some connection options that are otherwise can't be cha... |
| CVE-2026-13078 | HIGH | 7.7 | 0.3% | Jul 22, 2026 | A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered... |
| CVE-2026-13077 | HIGH | 7.1 | 0.4% | Jul 22, 2026 | A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read... |
| CVE-2026-13076 | HIGH | 7.1 | 0.4% | Jul 22, 2026 | An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by p... |
| CVE-2026-13075 | HIGH | 7.1 | 0.4% | Jul 22, 2026 | An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via th... |
| CVE-2026-13071 | HIGH | 7.1 | 0.4% | Jul 22, 2026 | An authenticated user with read access can cause the mongod process to be terminated through certain aggregation express... |
| CVE-2026-13069 | HIGH | 7.1 | 0.2% | Jul 22, 2026 | An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c... |
| CVE-2026-13067 | HIGH | 7.2 | 0.1% | Jul 22, 2026 | When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be v... |
| CVE-2026-13066 | HIGH | 7.1 | 0.2% | Jul 22, 2026 | Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i... |
| CVE-2026-13065 | HIGH | 7.1 | 0.3% | Jul 22, 2026 | A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator... |
| CVE-2026-13064 | HIGH | 7.1 | 0.4% | Jul 22, 2026 | Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in ... |
| CVE-2026-13062 | HIGH | 7.1 | 0.2% | Jul 22, 2026 | An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal ... |
| CVE-2026-13060 | HIGH | 7.1 | 0.2% | Jul 22, 2026 | An authenticated user with limited read privileges may be able to access documents from collections they are not authori... |
| CVE-2026-13059 | HIGH | 8.6 | 0.3% | Jul 22, 2026 | An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role... |
| CVE-2026-13056 | HIGH | 7.1 | 0.3% | Jul 22, 2026 | Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate object... |
| CVE-2026-13055 | HIGH | 7.1 | 0.3% | Jul 22, 2026 | The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)... |
| CVE-2026-22049 | HIGH | 8.7 | 0.3% | Jul 22, 2026 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnera... |
| CVE-2026-64835 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within l... |
| CVE-2026-64834 | HIGH | 8.7 | 0.5% | Jul 22, 2026 | FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtp... |
| CVE-2026-64833 | HIGH | 7.1 | 0.2% | Jul 22, 2026 | FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attacker... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now