2026 CVE Vulnerabilities
44,809 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63739 | HIGH | 8.3 | 0.3% | Jul 20, 2026 | SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows da... |
| CVE-2026-63737 | HIGH | 7.1 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server... |
| CVE-2026-63735 | HIGH | 8.6 | 0.3% | Jul 20, 2026 | SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticat... |
| CVE-2026-16247 | HIGH | 7.3 | 0.1% | Jul 20, 2026 | In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this proces... |
| CVE-2026-16246 | HIGH | 7.3 | 0.1% | Jul 20, 2026 | In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows g... |
| CVE-2026-14448 | HIGH | 8.6 | 0.8% | Jul 20, 2026 | An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi... |
| CVE-2026-13577 | HIGH | 8.2 | 0.3% | Jul 20, 2026 | Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dan... |
| CVE-2026-9833 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape... |
| CVE-2026-6656 | HIGH | 7.5 | 0.1% | Jul 20, 2026 | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the bu... |
| CVE-2026-13142 | HIGH | 8.1 | 0.1% | Jul 20, 2026 | The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a wo... |
| CVE-2026-12970 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attri... |
| CVE-2026-12592 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu... |
| CVE-2026-11349 | HIGH | 8.6 | 0.2% | Jul 20, 2026 | The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0... |
| CVE-2026-10081 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe... |
| CVE-2026-42566 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User... |
| CVE-2026-12484 | HIGH | 7.8 | 0.2% | Jul 19, 2026 | A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle d... |
| CVE-2026-64186 | HIGH | 7.1 | 0.2% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Remove latent out-of-bounds access in IO... |
| CVE-2026-64181 | HIGH | 7.8 | 0.1% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm: fix __vm_normal_page() to handle missing suppor... |
| CVE-2026-64178 | HIGH | 8.8 | 0.2% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_ad... |
| CVE-2026-64176 | HIGH | 8.1 | 0.2% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old ... |
| CVE-2026-64175 | HIGH | 7.5 | 0.3% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: stop TX during firmware restart... |
| CVE-2026-64172 | HIGH | 7.1 | 0.1% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Disable AVIC IPI virtualization on Hygon ... |
| CVE-2026-64158 | HIGH | 7.3 | 0.1% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix write streaming disablement if fd open O... |
| CVE-2026-64153 | HIGH | 8.8 | 0.1% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix iommu_map_sgtable() return value check... |
| CVE-2026-64152 | HIGH | 7.8 | 0.1% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu: Handle unmap error when iommu_debug is enabl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now