2026 CVE Vulnerabilities
44,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14741 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_da... |
| CVE-2026-12715 | HIGH | 8.5 | — | Jul 17, 2026 | Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an at... |
| CVE-2026-63094 | HIGH | 8.1 | 0.2% | Jul 17, 2026 | SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated... |
| CVE-2026-63093 | HIGH | 8.8 | 0.5% | Jul 17, 2026 | Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbit... |
| CVE-2026-51082 | HIGH | 7.2 | — | Jul 17, 2026 | A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager be... |
| CVE-2026-9592 | HIGH | 7.5 | — | Jul 17, 2026 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user sess... |
| CVE-2026-7488 | HIGH | 7.5 | — | Jul 17, 2026 | Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embed... |
| CVE-2026-16016 | HIGH | 7.3 | — | Jul 17, 2026 | A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file ex... |
| CVE-2026-8396 | HIGH | 7.5 | — | Jul 17, 2026 | Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Dat... |
| CVE-2026-7189 | HIGH | 7.5 | — | Jul 17, 2026 | Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessin... |
| CVE-2026-16014 | HIGH | 7.3 | 0.3% | Jul 17, 2026 | A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the compo... |
| CVE-2026-13410 | HIGH | 8.2 | 0.2% | Jul 17, 2026 | Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is in... |
| CVE-2026-59695 | HIGH | 8.3 | — | Jul 17, 2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f... |
| CVE-2026-59694 | HIGH | 8.3 | — | Jul 17, 2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the... |
| CVE-2026-59252 | HIGH | 8.2 | — | Jul 17, 2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the f... |
| CVE-2026-22104 | HIGH | 7.1 | 0.3% | Jul 17, 2026 | Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows... |
| CVE-2026-11961 | HIGH | 8.1 | 0.1% | Jul 17, 2026 | The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted d... |
| CVE-2026-11575 | HIGH | 7.5 | 0.1% | Jul 17, 2026 | The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming paymen... |
| CVE-2026-13765 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive... |
| CVE-2026-13352 | HIGH | 8.8 | 0.6% | Jul 17, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2026-15395 | HIGH | 7.2 | 0.2% | Jul 17, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-62387 | HIGH | 7.1 | 0.3% | Jul 17, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default C... |
| CVE-2026-62386 | HIGH | 8.2 | 0.3% | Jul 17, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query... |
| CVE-2026-62238 | HIGH | 8.8 | 0.2% | Jul 17, 2026 | OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint ... |
| CVE-2026-62234 | HIGH | 8.4 | 0.3% | Jul 17, 2026 | Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.w... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now