2026 CVE Vulnerabilities
43,564 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63742 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths... |
| CVE-2026-63741 | MEDIUM | 6.9 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS ... |
| CVE-2026-63738 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g... |
| CVE-2026-63736 | MEDIUM | 5.1 | 0.2% | Jul 20, 2026 | SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the ... |
| CVE-2026-63734 | MEDIUM | 6.9 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that allows aut... |
| CVE-2026-63733 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS... |
| CVE-2026-16254 | MEDIUM | 4.3 | — | Jul 20, 2026 | A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an o... |
| CVE-2026-15813 | MEDIUM | 6.5 | — | Jul 20, 2026 | A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The int... |
| CVE-2026-15588 | MEDIUM | 5.3 | — | Jul 20, 2026 | A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` a... |
| CVE-2026-2445 | MEDIUM | 6.1 | 0.1% | Jul 20, 2026 | The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encod... |
| CVE-2026-8825 | MEDIUM | 4.9 | 0.1% | Jul 20, 2026 | The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning p... |
| CVE-2026-13432 | MEDIUM | 5.4 | 0.1% | Jul 20, 2026 | The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing a... |
| CVE-2026-13156 | MEDIUM | 5.4 | 0.1% | Jul 20, 2026 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it veri... |
| CVE-2026-12973 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i... |
| CVE-2026-12972 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i... |
| CVE-2026-12898 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value be... |
| CVE-2026-12724 | MEDIUM | 4.3 | 0.1% | Jul 20, 2026 | The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re... |
| CVE-2026-12723 | MEDIUM | 5.3 | 0.1% | Jul 20, 2026 | The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u... |
| CVE-2026-11868 | MEDIUM | 5.3 | 0.1% | Jul 20, 2026 | The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio... |
| CVE-2026-10724 | MEDIUM | 4.8 | 0.1% | Jul 20, 2026 | The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review... |
| CVE-2026-45138 | MEDIUM | 5.4 | 0.1% | Jul 20, 2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` v... |
| CVE-2026-64185 | MEDIUM | 5.5 | 0.2% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: sysfs: don't remove existing directory on update fa... |
| CVE-2026-64184 | MEDIUM | 5.5 | 0.2% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: call missing mem_cgroup_ite... |
| CVE-2026-64183 | MEDIUM | 5.5 | 0.2% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: efi: Allocate runtime workqueue before ACPI init S... |
| CVE-2026-64182 | MEDIUM | 5.5 | 0.2% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: fix memory block reference lea... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now