2026 CVE Vulnerabilities
45,004 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57833 | HIGH | 8.6 | 0.4% | Jul 15, 2026 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vu... |
| CVE-2026-57821 | HIGH | 8.1 | 0.3% | Jul 15, 2026 | A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and ... |
| CVE-2026-56287 | HIGH | 8.1 | 0.3% | Jul 15, 2026 | A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versi... |
| CVE-2026-35152 | HIGH | 8.8 | 0.3% | Jul 15, 2026 | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to a... |
| CVE-2026-57832 | HIGH | 8.7 | 0.2% | Jul 15, 2026 | Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocma... |
| CVE-2026-57831 | HIGH | 8.7 | 0.2% | Jul 15, 2026 | Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla e... |
| CVE-2026-15804 | HIGH | 8.8 | 0.3% | Jul 15, 2026 | The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands ... |
| CVE-2026-15583 | HIGH | 8.6 | 0.3% | Jul 15, 2026 | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's enviro... |
| CVE-2026-14251 | HIGH | 7.7 | 0.2% | Jul 15, 2026 | A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when ... |
| CVE-2026-42936 | HIGH | 8.4 | 0.1% | Jul 15, 2026 | The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory wh... |
| CVE-2026-12512 | HIGH | 8.6 | 0.2% | Jul 15, 2026 | The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before us... |
| CVE-2026-12281 | HIGH | 8.1 | 0.1% | Jul 15, 2026 | The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without ... |
| CVE-2026-8920 | HIGH | 8.5 | 0.1% | Jul 15, 2026 | Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wa... |
| CVE-2026-8919 | HIGH | 7.2 | 0.3% | Jul 15, 2026 | Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local us... |
| CVE-2026-15029 | HIGH | 8.4 | 0.1% | Jul 15, 2026 | Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Mana... |
| CVE-2026-13585 | HIGH | 8.2 | 0.1% | Jul 15, 2026 | Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in ... |
| CVE-2026-15752 | HIGH | 7.3 | — | Jul 14, 2026 | A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is a... |
| CVE-2026-59733 | HIGH | 8.8 | 0.4% | Jul 14, 2026 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1... |
| CVE-2026-54684 | HIGH | 7 | 0.1% | Jul 14, 2026 | jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlle... |
| CVE-2026-54572 | HIGH | 8.8 | 0.3% | Jul 14, 2026 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1... |
| CVE-2026-50130 | HIGH | 8.8 | 0.2% | Jul 14, 2026 | Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From ... |
| CVE-2026-49981 | HIGH | 8.2 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is c... |
| CVE-2026-48808 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but... |
| CVE-2026-48352 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de... |
| CVE-2026-48351 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now