2026 CVE Vulnerabilities
43,188 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53976 | CRITICAL | 9.3 | — | Aug 6, 2026 | OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and... |
| CVE-2026-53975 | CRITICAL | 9.8 | — | Aug 6, 2026 | OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execu... |
| CVE-2026-34191 | CRITICAL | 9.1 | 0.3% | Aug 6, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Ru... |
| CVE-2026-32327 | CRITICAL | 9.1 | 0.3% | Aug 6, 2026 | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses ... |
| CVE-2026-28139 | CRITICAL | 9.8 | — | Aug 6, 2026 | Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. |
| CVE-2026-28005 | CRITICAL | 9.8 | — | Aug 6, 2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. |
| CVE-2026-64993 | CRITICAL | 9.1 | 0.1% | Aug 6, 2026 | Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo... |
| CVE-2026-5134 | CRITICAL | 9.8 | — | Aug 6, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info... |
| CVE-2026-12605 | CRITICAL | 9.6 | 0.2% | Aug 6, 2026 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfrestt... |
| CVE-2026-68079 | CRITICAL | 9.8 | — | Aug 6, 2026 | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of ... |
| CVE-2026-65583 | CRITICAL | 9.1 | — | Aug 6, 2026 | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim che... |
| CVE-2026-63687 | CRITICAL | 9.1 | — | Aug 6, 2026 | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map witho... |
| CVE-2026-61466 | CRITICAL | 9.1 | — | Aug 6, 2026 | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` val... |
| CVE-2026-66909 | CRITICAL | 9.8 | — | Aug 6, 2026 | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, wit... |
| CVE-2026-64597 | CRITICAL | 9.8 | 0.2% | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay... |
| CVE-2026-5430 | CRITICAL | 10 | 0.2% | Aug 6, 2026 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or support... |
| CVE-2026-1728 | CRITICAL | 9.8 | 0.3% | Aug 6, 2026 | Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level... |
| CVE-2026-16054 | CRITICAL | 9.1 | 0.1% | Aug 6, 2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated us... |
| CVE-2026-12713 | CRITICAL | 9.1 | 0.2% | Aug 6, 2026 | The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using i... |
| CVE-2026-67873 | CRITICAL | 9.8 | — | Aug 6, 2026 | A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occ... |
| CVE-2026-67870 | CRITICAL | 9.8 | 0.3% | Aug 6, 2026 | In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local E... |
| CVE-2026-67531 | CRITICAL | 9.3 | 0.4% | Aug 6, 2026 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:ex... |
| CVE-2026-52466 | CRITICAL | 9.8 | — | Aug 6, 2026 | Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to sto... |
| CVE-2026-71319 | CRITICAL | 9.6 | 0.3% | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) expos... |
| CVE-2026-70615 | CRITICAL | 9.9 | 0.2% | Aug 5, 2026 | boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users wit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now