2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44100 | CRITICAL | 9.4 | 0.3% | Jul 30, 2026 | The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to di... |
| CVE-2026-44092 | CRITICAL | 9.1 | 0.4% | Jul 30, 2026 | An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not vali... |
| CVE-2026-44091 | CRITICAL | 9.1 | 0.3% | Jul 30, 2026 | An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configura... |
| CVE-2026-44090 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected fr... |
| CVE-2026-58066 | CRITICAL | 9.8 | 0.2% | Jul 30, 2026 | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML ... |
| CVE-2026-58046 | CRITICAL | 9.9 | — | Jul 30, 2026 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL inject... |
| CVE-2026-14602 | CRITICAL | 9 | 0.3% | Jul 30, 2026 | The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, al... |
| CVE-2026-16610 | CRITICAL | 9.8 | 0.6% | Jul 30, 2026 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up... |
| CVE-2026-48449 | CRITICAL | 10 | 0.5% | Jul 30, 2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code... |
| CVE-2026-18015 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potenti... |
| CVE-2026-18002 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attac... |
| CVE-2026-17991 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who h... |
| CVE-2026-17990 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker... |
| CVE-2026-17987 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote att... |
| CVE-2026-17947 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a ... |
| CVE-2026-17940 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allo... |
| CVE-2026-17924 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer... |
| CVE-2026-17865 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had ... |
| CVE-2026-17856 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had... |
| CVE-2026-17855 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the render... |
| CVE-2026-17848 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sa... |
| CVE-2026-17847 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to... |
| CVE-2026-17837 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker... |
| CVE-2026-17834 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke... |
| CVE-2026-17832 | CRITICAL | 9.6 | 0.2% | Jul 30, 2026 | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the render... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now