2026 CVE Vulnerabilities
47,538 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10054 | HIGH | 8.8 | 0.2% | Jul 3, 2026 | In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc... |
| CVE-2026-47896 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen... |
| CVE-2026-9148 | HIGH | 7.2 | 0.3% | Jul 3, 2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Websi... |
| CVE-2026-47897 | HIGH | 7.5 | 0.4% | Jul 3, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen... |
| CVE-2026-9547 | HIGH | 7.4 | 0.4% | Jul 3, 2026 | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION`... |
| CVE-2026-9546 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the document... |
| CVE-2026-9545 | HIGH | 7.5 | 0.3% | Jul 3, 2026 | In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transf... |
| CVE-2026-9080 | HIGH | 7.3 | 0.4% | Jul 3, 2026 | Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerab... |
| CVE-2026-8932 | HIGH | 7.5 | 0.1% | Jul 3, 2026 | libcurl would reuse a previously created connection even when some mTLS config related option had been changed that shou... |
| CVE-2026-8286 | HIGH | 8.1 | 0.4% | Jul 3, 2026 | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live co... |
| CVE-2026-4967 | HIGH | 7.5 | 0.4% | Jul 3, 2026 | In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of servic... |
| CVE-2026-12064 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe... |
| CVE-2026-11586 | HIGH | 7.5 | 0.6% | Jul 3, 2026 | By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation... |
| CVE-2026-11352 | HIGH | 7.5 | 0.8% | Jul 3, 2026 | An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service agai... |
| CVE-2026-14352 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8... |
| CVE-2026-13040 | HIGH | 7.2 | 0.3% | Jul 3, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2026-8921 | HIGH | 8.5 | 0.1% | Jul 3, 2026 | External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary co... |
| CVE-2026-14327 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.4... |
| CVE-2026-8247 | HIGH | 8.8 | 0.2% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local n... |
| CVE-2026-13722 | HIGH | 7.2 | 0.2% | Jul 3, 2026 | WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore featu... |
| CVE-2026-13384 | HIGH | 7.2 | 0.6% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged u... |
| CVE-2026-13383 | HIGH | 7.2 | 0.6% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged ... |
| CVE-2026-13368 | HIGH | 8.1 | 0.9% | Jul 3, 2026 | WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for th... |
| CVE-2026-13084 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create... |
| CVE-2026-13079 | HIGH | 7.8 | 0.1% | Jul 3, 2026 | A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attac... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now