2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16250 | CRITICAL | 9.8 | 0.2% | Aug 3, 2026 | The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an un... |
| CVE-2026-16060 | CRITICAL | 9.8 | 0.2% | Aug 3, 2026 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the conten... |
| CVE-2026-15930 | CRITICAL | 9.4 | 0.1% | Aug 3, 2026 | The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration bef... |
| CVE-2026-14557 | CRITICAL | 9.1 | 0.2% | Aug 3, 2026 | The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token i... |
| CVE-2026-12965 | CRITICAL | 9.1 | 0.2% | Aug 3, 2026 | The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action befo... |
| CVE-2026-12872 | CRITICAL | 9.8 | 0.3% | Aug 3, 2026 | The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload ... |
| CVE-2026-58062 | CRITICAL | 9.3 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This i... |
| CVE-2026-8763 | CRITICAL | 9.3 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also a... |
| CVE-2026-59650 | CRITICAL | 9.3 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects... |
| CVE-2026-59638 | CRITICAL | 9.3 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. ... |
| CVE-2026-65321 | CRITICAL | 9.8 | 0.4% | Aug 2, 2026 | PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrar... |
| CVE-2026-68582 | CRITICAL | 9.3 | 0.2% | Aug 2, 2026 | Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-col... |
| CVE-2026-68579 | CRITICAL | 9.6 | 0.3% | Aug 2, 2026 | FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_... |
| CVE-2026-16256 | CRITICAL | 9.8 | 0.1% | Aug 2, 2026 | The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions av... |
| CVE-2026-8457 | CRITICAL | 9.8 | 0.4% | Aug 2, 2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc... |
| CVE-2026-67342 | CRITICAL | 9.8 | 0.3% | Aug 1, 2026 | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, P... |
| CVE-2026-67341 | CRITICAL | 9.8 | 0.3% | Aug 1, 2026 | ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with... |
| CVE-2026-67340 | CRITICAL | 9.8 | 0.5% | Aug 1, 2026 | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) b... |
| CVE-2026-67336 | CRITICAL | 9.4 | 0.2% | Aug 1, 2026 | better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that adve... |
| CVE-2026-67330 | CRITICAL | 9.9 | 0.4% | Aug 1, 2026 | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.... |
| CVE-2026-67324 | CRITICAL | 9.8 | 0.4% | Aug 1, 2026 | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>... |
| CVE-2026-67308 | CRITICAL | 9.3 | 0.5% | Aug 1, 2026 | Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execut... |
| CVE-2026-67305 | CRITICAL | 9.4 | 0.5% | Aug 1, 2026 | FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when... |
| CVE-2026-67294 | CRITICAL | 9.3 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si... |
| CVE-2026-67293 | CRITICAL | 9.3 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now