2026 CVE Vulnerabilities
43,380 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63047 | HIGH | 7.5 | 0.2% | Jul 22, 2026 | Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - ... |
| CVE-2026-3821 | HIGH | 8.8 | 0.6% | Jul 22, 2026 | Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attack... |
| CVE-2026-12987 | HIGH | 7.5 | 0.2% | Jul 22, 2026 | The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-Use... |
| CVE-2026-12968 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthent... |
| CVE-2026-15802 | HIGH | 8.1 | 0.5% | Jul 22, 2026 | The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation... |
| CVE-2026-56844 | HIGH | 8.4 | 0.1% | Jul 22, 2026 | A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate ... |
| CVE-2026-56819 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug... |
| CVE-2026-16423 | HIGH | 8.8 | 0.2% | Jul 21, 2026 | Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage i... |
| CVE-2026-16422 | HIGH | 7.5 | 0.1% | Jul 21, 2026 | Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an a... |
| CVE-2026-16421 | HIGH | 8.8 | 0.2% | Jul 21, 2026 | Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute a... |
| CVE-2026-16420 | HIGH | 8.8 | 0.2% | Jul 21, 2026 | Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code ... |
| CVE-2026-16418 | HIGH | 8.8 | 0.2% | Jul 21, 2026 | Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-16414 | HIGH | 7.8 | 0.1% | Jul 21, 2026 | Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attack... |
| CVE-2026-16413 | HIGH | 8.3 | 0.2% | Jul 21, 2026 | Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the ... |
| CVE-2026-8987 | HIGH | 8.8 | 0.4% | Jul 21, 2026 | Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command ha... |
| CVE-2026-65319 | HIGH | 8.7 | 0.4% | Jul 21, 2026 | Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated at... |
| CVE-2026-65316 | HIGH | 7.1 | 0.4% | Jul 21, 2026 | XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read... |
| CVE-2026-65315 | HIGH | 8.7 | 0.6% | Jul 21, 2026 | Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows r... |
| CVE-2026-62574 | HIGH | 7.8 | 0.1% | Jul 21, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2026-62567 | HIGH | 7.7 | 0.2% | Jul 21, 2026 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th... |
| CVE-2026-62565 | HIGH | 7.1 | 0.2% | Jul 21, 2026 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported ve... |
| CVE-2026-62561 | HIGH | 7.8 | 0.1% | Jul 21, 2026 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve... |
| CVE-2026-62560 | HIGH | 7.7 | 0.2% | Jul 21, 2026 | Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supporte... |
| CVE-2026-62557 | HIGH | 7.1 | 0.2% | Jul 21, 2026 | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th... |
| CVE-2026-62548 | HIGH | 7.2 | 0.3% | Jul 21, 2026 | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now