2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58155 | CRITICAL | 9.3 | 0.3% | Jul 29, 2026 | Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. ... |
| CVE-2026-58154 | CRITICAL | 9.2 | 0.3% | Jul 29, 2026 | Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affe... |
| CVE-2026-58150 | CRITICAL | 10 | 0.2% | Jul 29, 2026 | Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This ... |
| CVE-2026-57834 | CRITICAL | 10 | 0.3% | Jul 29, 2026 | Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Ser... |
| CVE-2026-41920 | CRITICAL | 9.3 | 0.2% | Jul 29, 2026 | Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 th... |
| CVE-2026-33267 | CRITICAL | 9.1 | 0.2% | Jul 29, 2026 | Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 ... |
| CVE-2026-18191 | CRITICAL | 9.8 | 0.4% | Jul 29, 2026 | VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to... |
| CVE-2026-63234 | CRITICAL | 9.9 | 0.3% | Jul 29, 2026 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro... |
| CVE-2026-63233 | CRITICAL | 9.9 | 0.3% | Jul 29, 2026 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro... |
| CVE-2026-63232 | CRITICAL | 9.9 | 0.3% | Jul 29, 2026 | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject thro... |
| CVE-2026-63230 | CRITICAL | 9.1 | 0.3% | Jul 29, 2026 | A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read ... |
| CVE-2026-63229 | CRITICAL | 9.1 | 0.3% | Jul 29, 2026 | A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-... |
| CVE-2026-63227 | CRITICAL | 9.9 | 0.3% | Jul 29, 2026 | An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCOR... |
| CVE-2026-13423 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauth... |
| CVE-2026-18072 | CRITICAL | 9.8 | 0.6% | Jul 29, 2026 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to ... |
| CVE-2026-64863 | CRITICAL | 9.1 | 0.3% | Jul 28, 2026 | goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.... |
| CVE-2026-62325 | CRITICAL | 9.1 | 0.3% | Jul 28, 2026 | goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver... |
| CVE-2026-54658 | CRITICAL | 9.8 | 0.4% | Jul 28, 2026 | Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/u... |
| CVE-2026-6881 | CRITICAL | 9.4 | — | Jul 28, 2026 | A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated a... |
| CVE-2026-14976 | CRITICAL | 9.8 | 0.2% | Jul 28, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the colle... |
| CVE-2026-14974 | CRITICAL | 9.8 | 0.4% | Jul 28, 2026 | IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused... |
| CVE-2026-14973 | CRITICAL | 9.3 | 0.5% | Jul 28, 2026 | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's s... |
| CVE-2026-14512 | CRITICAL | 9.8 | 0.5% | Jul 28, 2026 | IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization whi... |
| CVE-2026-14446 | CRITICAL | 9.8 | 0.3% | Jul 28, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the adminis... |
| CVE-2026-16184 | CRITICAL | 9.8 | 0.3% | Jul 28, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafte... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now