2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19073 | MEDIUM | 5.3 | — | Aug 12, 2026 | The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o... |
| CVE-2026-19052 | MEDIUM | 4.3 | — | Aug 12, 2026 | The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac... |
| CVE-2026-19050 | MEDIUM | 6.4 | — | Aug 12, 2026 | The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the ca... |
| CVE-2026-18962 | MEDIUM | 4.3 | — | Aug 12, 2026 | The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int... |
| CVE-2026-18943 | MEDIUM | 6.5 | — | Aug 12, 2026 | The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow... |
| CVE-2026-12235 | MEDIUM | 6.3 | — | Aug 12, 2026 | The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (p... |
| CVE-2026-12233 | MEDIUM | 5.9 | — | Aug 12, 2026 | The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre... |
| CVE-2026-12232 | MEDIUM | 6.1 | — | Aug 12, 2026 | The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a cal... |
| CVE-2026-9318 | MEDIUM | 5.4 | — | Aug 12, 2026 | tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows... |
| CVE-2026-19588 | MEDIUM | 6.5 | — | Aug 12, 2026 | Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. |
| CVE-2026-19587 | MEDIUM | 6.5 | — | Aug 12, 2026 | Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation. |
| CVE-2026-64927 | MEDIUM | 6.4 | — | Aug 12, 2026 | A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissio... |
| CVE-2026-73250 | MEDIUM | 5.4 | — | Aug 11, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer... |
| CVE-2026-73245 | MEDIUM | 6.5 | — | Aug 11, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/appli... |
| CVE-2026-66340 | MEDIUM | 6.9 | — | Aug 11, 2026 | The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout ... |
| CVE-2026-64934 | MEDIUM | 5.3 | — | Aug 11, 2026 | The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho... |
| CVE-2026-66832 | MEDIUM | 6.9 | — | Aug 11, 2026 | When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app... |
| CVE-2026-66148 | MEDIUM | 6.3 | — | Aug 11, 2026 | An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.10... |
| CVE-2026-63134 | MEDIUM | 5.4 | — | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w... |
| CVE-2026-63133 | MEDIUM | 6.5 | — | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives... |
| CVE-2026-48762 | MEDIUM | 5.4 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u... |
| CVE-2026-29035 | MEDIUM | 6.5 | — | Aug 11, 2026 | CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that... |
| CVE-2026-19579 | MEDIUM | 5.4 | — | Aug 11, 2026 | Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request ... |
| CVE-2026-19550 | MEDIUM | 4.3 | — | Aug 11, 2026 | A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath... |
| CVE-2026-73282 | MEDIUM | 4.8 | — | Aug 11, 2026 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now