2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66150 | HIGH | 7.8 | — | Aug 11, 2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows... |
| CVE-2026-66149 | HIGH | 7.8 | — | Aug 11, 2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows... |
| CVE-2026-63177 | HIGH | 7.1 | — | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng... |
| CVE-2026-55676 | HIGH | 8.8 | — | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `P... |
| CVE-2026-48763 | HIGH | 8.2 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t... |
| CVE-2026-15606 | HIGH | 8.8 | — | Aug 11, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i... |
| CVE-2026-14863 | HIGH | 8.8 | — | Aug 11, 2026 | FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated at... |
| CVE-2026-73242 | HIGH | 8.3 | — | Aug 11, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos... |
| CVE-2026-73241 | HIGH | 8.3 | — | Aug 11, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreer... |
| CVE-2026-73234 | HIGH | 7.8 | — | Aug 11, 2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() i... |
| CVE-2026-73233 | HIGH | 8.5 | — | Aug 11, 2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint t... |
| CVE-2026-73232 | HIGH | 7.5 | — | Aug 11, 2026 | ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory... |
| CVE-2026-73231 | HIGH | 7.8 | — | Aug 11, 2026 | Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method ... |
| CVE-2026-73031 | HIGH | 8.7 | — | Aug 11, 2026 | telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary J... |
| CVE-2026-71467 | HIGH | 7.5 | — | Aug 11, 2026 | A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authent... |
| CVE-2026-48813 | HIGH | 8.7 | — | Aug 11, 2026 | Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have a... |
| CVE-2026-48804 | HIGH | 7.5 | — | Aug 11, 2026 | python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server store... |
| CVE-2026-19091 | HIGH | 8.1 | — | Aug 11, 2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ... |
| CVE-2026-18844 | HIGH | 8.1 | — | Aug 11, 2026 | The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (... |
| CVE-2026-13457 | HIGH | 7.5 | — | Aug 11, 2026 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all ... |
| CVE-2026-73227 | HIGH | 8.1 | — | Aug 11, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al... |
| CVE-2026-73226 | HIGH | 8.8 | — | Aug 11, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm al... |
| CVE-2026-73225 | HIGH | 8.1 | — | Aug 11, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al... |
| CVE-2026-73224 | HIGH | 8.8 | — | Aug 11, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al... |
| CVE-2026-73223 | HIGH | 8.1 | — | Aug 11, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now