2026 CVE Vulnerabilities
44,078 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46987 | HIGH | 7.7 | 0.2% | Jul 21, 2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Applicatio... |
| CVE-2026-46981 | HIGH | 7.2 | 0.2% | Jul 21, 2026 | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mob... |
| CVE-2026-46954 | HIGH | 7.2 | 0.4% | Jul 21, 2026 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). Supporte... |
| CVE-2026-46943 | HIGH | 7.4 | 0.3% | Jul 21, 2026 | Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported ve... |
| CVE-2026-46941 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported... |
| CVE-2026-46923 | HIGH | 8 | 0.3% | Jul 21, 2026 | Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Auth... |
| CVE-2026-43947 | HIGH | 8.9 | 0.7% | Jul 21, 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Co... |
| CVE-2026-43946 | HIGH | 7.7 | 0.5% | Jul 21, 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in t... |
| CVE-2026-43945 | HIGH | 8.9 | 0.9% | Jul 21, 2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthent... |
| CVE-2026-35287 | HIGH | 7.5 | 0.3% | Jul 21, 2026 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita... |
| CVE-2026-16484 | HIGH | 7.3 | 0.4% | Jul 21, 2026 | A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2026-10680 | HIGH | 7.6 | 0.1% | Jul 21, 2026 | The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/class... |
| CVE-2026-10678 | HIGH | 8.1 | 0.3% | Jul 21, 2026 | The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writ... |
| CVE-2026-8982 | HIGH | 8.1 | 0.3% | Jul 21, 2026 | Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vend... |
| CVE-2026-65056 | HIGH | 8.3 | 0.2% | Jul 21, 2026 | mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw... |
| CVE-2026-65054 | HIGH | 8.2 | 0.2% | Jul 21, 2026 | MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media ... |
| CVE-2026-64881 | HIGH | 8.8 | 1.4% | Jul 21, 2026 | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command exe... |
| CVE-2026-63764 | HIGH | 8.6 | 0.3% | Jul 21, 2026 | LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _lo... |
| CVE-2026-63358 | HIGH | 8.4 | 0.1% | Jul 21, 2026 | FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P... |
| CVE-2026-63080 | HIGH | 7.1 | 0.2% | Jul 21, 2026 | Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authe... |
| CVE-2026-56147 | HIGH | 7.1 | 0.3% | Jul 21, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and... |
| CVE-2026-52476 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPage... |
| CVE-2026-52474 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file. |
| CVE-2026-47697 | HIGH | 7.1 | 0.2% | Jul 21, 2026 | Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). ... |
| CVE-2026-47695 | HIGH | 7.1 | 0.3% | Jul 21, 2026 | CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now