2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18171 | MEDIUM | 5.7 | — | Aug 12, 2026 | Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the und... |
| CVE-2026-14479 | MEDIUM | 5.5 | — | Aug 12, 2026 | A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation ... |
| CVE-2026-47232 | MEDIUM | 4.3 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modu... |
| CVE-2026-47230 | MEDIUM | 6.5 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_re... |
| CVE-2026-47229 | MEDIUM | 5.4 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm... |
| CVE-2026-47228 | MEDIUM | 5.2 | — | Aug 12, 2026 | Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random pa... |
| CVE-2026-47227 | MEDIUM | 6.5 | — | Aug 12, 2026 | Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (... |
| CVE-2026-16999 | MEDIUM | 6.3 | — | Aug 12, 2026 | Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows S... |
| CVE-2026-71408 | MEDIUM | 5.3 | — | Aug 12, 2026 | A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.... |
| CVE-2026-71407 | MEDIUM | 5.6 | — | Aug 12, 2026 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an... |
| CVE-2026-70466 | MEDIUM | 5.3 | — | Aug 12, 2026 | A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.... |
| CVE-2026-47226 | MEDIUM | 6.5 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload... |
| CVE-2026-70560 | MEDIUM | 5.4 | — | Aug 12, 2026 | Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-pri... |
| CVE-2026-17008 | MEDIUM | 5.3 | — | Aug 12, 2026 | The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status i... |
| CVE-2026-16990 | MEDIUM | 5.3 | — | Aug 12, 2026 | The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-si... |
| CVE-2026-16747 | MEDIUM | 6.5 | — | Aug 12, 2026 | The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes... |
| CVE-2026-16621 | MEDIUM | 5.3 | — | Aug 12, 2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succee... |
| CVE-2026-15213 | MEDIUM | 5.3 | — | Aug 12, 2026 | The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-... |
| CVE-2026-15045 | MEDIUM | 6.5 | — | Aug 12, 2026 | The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against... |
| CVE-2026-67284 | MEDIUM | 5.3 | — | Aug 12, 2026 | Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authentica... |
| CVE-2026-64955 | MEDIUM | 6.1 | — | Aug 12, 2026 | When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CS... |
| CVE-2026-64952 | MEDIUM | 6.5 | — | Aug 12, 2026 | The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLL... |
| CVE-2026-18663 | MEDIUM | 5.9 | — | Aug 12, 2026 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess... |
| CVE-2026-18652 | MEDIUM | 4.9 | — | Aug 12, 2026 | Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within... |
| CVE-2026-67283 | MEDIUM | 6.9 | — | Aug 12, 2026 | Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now