2026 CVE Vulnerabilities
46,870 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33390 | HIGH | 8.1 | 0.2% | Jul 9, 2026 | An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors r... |
| CVE-2026-31985 | HIGH | 8.3 | 0.1% | Jul 9, 2026 | When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disab... |
| CVE-2026-31984 | HIGH | 8.7 | 0.3% | Jul 9, 2026 | A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functional... |
| CVE-2026-31982 | HIGH | 7.1 | 0.2% | Jul 9, 2026 | An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of... |
| CVE-2026-15000 | HIGH | 7.2 | 0.3% | Jul 9, 2026 | The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp... |
| CVE-2026-47831 | HIGH | 7.7 | 0.2% | Jul 9, 2026 | Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-... |
| CVE-2026-47830 | HIGH | 8.8 | 0.1% | Jul 9, 2026 | Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege ... |
| CVE-2026-47829 | HIGH | 7.8 | 0.3% | Jul 9, 2026 | Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-s... |
| CVE-2026-47828 | HIGH | 8.8 | 0.1% | Jul 9, 2026 | During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new ... |
| CVE-2026-11571 | HIGH | 7.5 | 0.1% | Jul 9, 2026 | The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-not... |
| CVE-2026-5523 | HIGH | 8.8 | 0.3% | Jul 9, 2026 | The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.... |
| CVE-2026-41857 | HIGH | 7.8 | 0.1% | Jul 9, 2026 | A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the ope... |
| CVE-2026-15137 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code... |
| CVE-2026-15135 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the f... |
| CVE-2026-15134 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is... |
| CVE-2026-59723 | HIGH | 8.8 | 0.1% | Jul 8, 2026 | Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. Prior to 3.0.30, the Cline Hub dashboard... |
| CVE-2026-54784 | HIGH | 7.4 | 0.2% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF ... |
| CVE-2026-54783 | HIGH | 7.4 | 0.1% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-54781 | HIGH | 7.4 | 0.2% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-54774 | HIGH | 7.4 | 0.1% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-54772 | HIGH | 7.5 | 0.5% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-54499 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human language... |
| CVE-2026-15133 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary... |
| CVE-2026-15132 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-15129 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now