2026 CVE Vulnerabilities
43,188 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71278 | CRITICAL | 9.8 | 0.5% | Aug 5, 2026 | rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) cont... |
| CVE-2026-71277 | CRITICAL | 9.1 | 0.2% | Aug 5, 2026 | rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP ... |
| CVE-2026-71268 | CRITICAL | 9.9 | 0.6% | Aug 5, 2026 | OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.s... |
| CVE-2026-71267 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name... |
| CVE-2026-71263 | CRITICAL | 9.1 | 0.3% | Aug 5, 2026 | The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). Th... |
| CVE-2026-71262 | CRITICAL | 9.8 | 0.6% | Aug 5, 2026 | IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (... |
| CVE-2026-71256 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_iden... |
| CVE-2026-71254 | CRITICAL | 9.8 | 0.5% | Aug 5, 2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (F... |
| CVE-2026-71248 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw P... |
| CVE-2026-71238 | CRITICAL | 9.1 | 0.3% | Aug 5, 2026 | DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from ... |
| CVE-2026-71237 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sa... |
| CVE-2026-71231 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decod... |
| CVE-2026-66747 | CRITICAL | 9.8 | — | Aug 5, 2026 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across ... |
| CVE-2026-44945 | CRITICAL | 9.1 | 0.7% | Aug 5, 2026 | A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An... |
| CVE-2026-10090 | CRITICAL | 9.1 | 0.2% | Aug 5, 2026 | A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cl... |
| CVE-2026-10059 | CRITICAL | 9.1 | 0.3% | Aug 5, 2026 | A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namesp... |
| CVE-2026-71214 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasur... |
| CVE-2026-71213 | CRITICAL | 9.1 | 0.4% | Aug 5, 2026 | Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting,... |
| CVE-2026-71207 | CRITICAL | 9.8 | 0.7% | Aug 5, 2026 | The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its aut... |
| CVE-2026-70376 | CRITICAL | 9.6 | 0.2% | Aug 5, 2026 | Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.adm... |
| CVE-2026-64566 | CRITICAL | 9.8 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_s... |
| CVE-2026-61486 | CRITICAL | 9.8 | 0.4% | Aug 5, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Luc... |
| CVE-2026-61484 | CRITICAL | 9.8 | 0.4% | Aug 5, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac... |
| CVE-2026-5581 | CRITICAL | 9.1 | 0.5% | Aug 5, 2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all ... |
| CVE-2026-4431 | CRITICAL | 9.1 | 0.3% | Aug 5, 2026 | The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now