2026 CVE Vulnerabilities
43,635 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15007 | MEDIUM | 5.7 | — | Jul 17, 2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause... |
| CVE-2026-51083 | MEDIUM | 6.5 | — | Jul 17, 2026 | Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows u... |
| CVE-2026-51081 | MEDIUM | 6.1 | — | Jul 17, 2026 | A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environmen... |
| CVE-2026-16089 | MEDIUM | 5.9 | 0.1% | Jul 17, 2026 | A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 aut... |
| CVE-2026-16017 | MEDIUM | 6.3 | — | Jul 17, 2026 | A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file to... |
| CVE-2026-12705 | MEDIUM | 6.4 | — | Jul 17, 2026 | Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue a... |
| CVE-2026-16072 | MEDIUM | 4.9 | 0.2% | Jul 17, 2026 | A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to mana... |
| CVE-2026-16015 | MEDIUM | 6.3 | — | Jul 17, 2026 | A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of ... |
| CVE-2026-13082 | MEDIUM | 5.3 | — | Jul 17, 2026 | GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge ... |
| CVE-2026-16013 | MEDIUM | 5.5 | — | Jul 17, 2026 | A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this is... |
| CVE-2026-16009 | MEDIUM | 6.3 | — | Jul 17, 2026 | A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file... |
| CVE-2026-15943 | MEDIUM | 5.5 | 0.2% | Jul 17, 2026 | A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The is... |
| CVE-2026-9602 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the D... |
| CVE-2026-8075 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Matter... |
| CVE-2026-16008 | MEDIUM | 6.3 | — | Jul 17, 2026 | A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parseP... |
| CVE-2026-62764 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user... |
| CVE-2026-9656 | MEDIUM | 4.3 | 0.2% | Jul 17, 2026 | The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information ... |
| CVE-2026-15380 | MEDIUM | 5.1 | 0.1% | Jul 17, 2026 | A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — n... |
| CVE-2026-15379 | MEDIUM | 5.1 | 0.1% | Jul 17, 2026 | The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents ... |
| CVE-2026-13402 | MEDIUM | 5.3 | 0.1% | Jul 17, 2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the tem... |
| CVE-2026-12393 | MEDIUM | 5.4 | 0.1% | Jul 17, 2026 | The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requ... |
| CVE-2026-11966 | MEDIUM | 5.3 | 0.1% | Jul 17, 2026 | The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticate... |
| CVE-2026-10525 | MEDIUM | 6.1 | 0.2% | Jul 17, 2026 | The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and... |
| CVE-2026-15094 | MEDIUM | 6.1 | 0.2% | Jul 17, 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parame... |
| CVE-2026-60060 | MEDIUM | 6.3 | 0.3% | Jul 17, 2026 | Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provide... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now