2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67305 | CRITICAL | 9.4 | 0.5% | Aug 1, 2026 | FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when... |
| CVE-2026-67294 | CRITICAL | 9.3 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si... |
| CVE-2026-67293 | CRITICAL | 9.3 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. ... |
| CVE-2026-67292 | CRITICAL | 9.3 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor... |
| CVE-2026-67289 | CRITICAL | 9.8 | 0.4% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controll... |
| CVE-2026-66402 | CRITICAL | 9.8 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in ... |
| CVE-2026-15964 | CRITICAL | 9.8 | 0.5% | Aug 1, 2026 | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password rese... |
| CVE-2026-13596 | CRITICAL | 9.1 | 0.2% | Aug 1, 2026 | The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied paramete... |
| CVE-2026-3141 | CRITICAL | 9.1 | 0.5% | Aug 1, 2026 | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability chec... |
| CVE-2026-68771 | CRITICAL | 9.8 | 0.6% | Jul 31, 2026 | ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthentic... |
| CVE-2026-52134 | CRITICAL | 9.8 | 0.3% | Jul 31, 2026 | An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass au... |
| CVE-2026-68770 | CRITICAL | 9.8 | 0.5% | Jul 31, 2026 | sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code e... |
| CVE-2026-51785 | CRITICAL | 9.8 | 0.4% | Jul 31, 2026 | An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted req... |
| CVE-2026-38713 | CRITICAL | 9.8 | 1.2% | Jul 31, 2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2... |
| CVE-2026-38708 | CRITICAL | 9.8 | 1.2% | Jul 31, 2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2... |
| CVE-2026-38711 | CRITICAL | 9.8 | 1.2% | Jul 31, 2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2... |
| CVE-2026-54725 | CRITICAL | 9.6 | — | Jul 31, 2026 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1... |
| CVE-2026-21662 | CRITICAL | 9.8 | 0.4% | Jul 31, 2026 | Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malic... |
| CVE-2026-67822 | CRITICAL | 9.8 | — | Jul 31, 2026 | Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu... |
| CVE-2026-58048 | CRITICAL | 9.4 | 0.6% | Jul 31, 2026 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. |
| CVE-2026-52855 | CRITICAL | 9.9 | — | Jul 31, 2026 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{... |
| CVE-2026-17566 | CRITICAL | 9.9 | 0.4% | Jul 31, 2026 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query in... |
| CVE-2026-17351 | CRITICAL | 9 | 0.4% | Jul 31, 2026 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu... |
| CVE-2026-17349 | CRITICAL | 9.6 | 0.3% | Jul 31, 2026 | /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of ... |
| CVE-2026-16504 | CRITICAL | 9.8 | 0.1% | Jul 31, 2026 | Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database passw... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now