2026 CVE Vulnerabilities
45,099 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15543 | HIGH | 8.8 | 0.5% | Jul 13, 2026 | A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertList... |
| CVE-2026-15542 | HIGH | 7.3 | 0.4% | Jul 13, 2026 | A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.g... |
| CVE-2026-15541 | HIGH | 7.3 | 0.3% | Jul 13, 2026 | A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file a... |
| CVE-2026-14165 | HIGH | 7.5 | 0.2% | Jul 13, 2026 | An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through ... |
| CVE-2026-15537 | HIGH | 7.3 | 0.3% | Jul 13, 2026 | A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown c... |
| CVE-2026-12582 | HIGH | 8.6 | 0.2% | Jul 13, 2026 | The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter befor... |
| CVE-2026-12275 | HIGH | 7.1 | 0.1% | Jul 13, 2026 | The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enr... |
| CVE-2026-11963 | HIGH | 8.1 | 0.1% | Jul 13, 2026 | The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membershi... |
| CVE-2026-9492 | HIGH | 8.5 | 0.1% | Jul 13, 2026 | The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an ... |
| CVE-2026-7162 | HIGH | 7.8 | 0.1% | Jul 13, 2026 | Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to ... |
| CVE-2026-15517 | HIGH | 7.3 | 0.3% | Jul 13, 2026 | A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSumma... |
| CVE-2026-15515 | HIGH | 7 | 0.1% | Jul 13, 2026 | A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown process... |
| CVE-2026-15514 | HIGH | 7.3 | 0.3% | Jul 13, 2026 | A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This vulnerability affects the function RPCS... |
| CVE-2026-15506 | HIGH | 7.8 | 0.2% | Jul 12, 2026 | A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown func... |
| CVE-2026-10667 | HIGH | 7.8 | 0.1% | Jul 12, 2026 | Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-l... |
| CVE-2026-10665 | HIGH | 7.4 | 0.4% | Jul 12, 2026 | In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearizes an inbou... |
| CVE-2026-58596 | HIGH | 8.3 | 0.5% | Jul 12, 2026 | Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges o... |
| CVE-2026-61875 | HIGH | 8.8 | 0.3% | Jul 12, 2026 | luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject Jav... |
| CVE-2026-59260 | HIGH | 8.8 | 0.7% | Jul 12, 2026 | OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users t... |
| CVE-2026-56313 | HIGH | 8.1 | 0.3% | Jul 12, 2026 | Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that al... |
| CVE-2026-56308 | HIGH | 8.4 | 0.2% | Jul 12, 2026 | Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification ... |
| CVE-2026-56259 | HIGH | 8.8 | 0.3% | Jul 12, 2026 | Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to ... |
| CVE-2026-56241 | HIGH | 8.3 | 0.2% | Jul 12, 2026 | Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to del... |
| CVE-2026-56238 | HIGH | 8.7 | 0.4% | Jul 12, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint t... |
| CVE-2026-15498 | HIGH | 7.3 | 0.3% | Jul 12, 2026 | A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. This impact... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now