2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16503 | CRITICAL | 9.1 | 0.1% | Jul 31, 2026 | Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces ... |
| CVE-2026-17561 | CRITICAL | 9.8 | — | Jul 31, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Cons... |
| CVE-2026-18452 | CRITICAL | 10 | 0.4% | Jul 31, 2026 | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote att... |
| CVE-2026-14919 | CRITICAL | 9.8 | 0.1% | Jul 31, 2026 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it be... |
| CVE-2026-14483 | CRITICAL | 9.8 | 0.6% | Jul 31, 2026 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver... |
| CVE-2026-63223 | CRITICAL | 9.8 | 0.5% | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not i... |
| CVE-2026-63221 | CRITICAL | 9.4 | — | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound v... |
| CVE-2026-43830 | CRITICAL | 9.8 | 0.1% | Jul 31, 2026 | Full details and mitigation steps are currently restricted and will be published at a later date. |
| CVE-2026-14537 | CRITICAL | 9.8 | 0.2% | Jul 31, 2026 | Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0... |
| CVE-2026-66421 | CRITICAL | 9.3 | 0.4% | Jul 30, 2026 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to ... |
| CVE-2026-38709 | CRITICAL | 9.8 | — | Jul 30, 2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2... |
| CVE-2026-68503 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships def... |
| CVE-2026-68502 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.... |
| CVE-2026-66803 | CRITICAL | 10 | 0.5% | Jul 30, 2026 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66418 | CRITICAL | 9.3 | 0.3% | Jul 30, 2026 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attack... |
| CVE-2026-52539 | CRITICAL | 9.1 | — | Jul 30, 2026 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not se... |
| CVE-2026-35847 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the Chec... |
| CVE-2026-67594 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attac... |
| CVE-2026-67208 | CRITICAL | 9.8 | — | Jul 30, 2026 | Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to exec... |
| CVE-2026-66756 | CRITICAL | 9.8 | 0.3% | Jul 30, 2026 | Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 ... |
| CVE-2026-12946 | CRITICAL | 9.9 | 0.3% | Jul 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the i... |
| CVE-2026-66066 | CRITICAL | 9.5 | 1.7% | Jul 30, 2026 | Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.... |
| CVE-2026-48499 | CRITICAL | 9.3 | — | Jul 30, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code... |
| CVE-2026-15976 | CRITICAL | 9.8 | 0.3% | Jul 30, 2026 | SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wi... |
| CVE-2026-15971 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when D... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now