2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17191 | CRITICAL | 9.1 | 2.8% | Jul 27, 2026 | An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this... |
| CVE-2026-66398 | CRITICAL | 9.4 | 0.2% | Jul 27, 2026 | phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated... |
| CVE-2026-66396 | CRITICAL | 9.3 | 0.3% | Jul 27, 2026 | SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cov... |
| CVE-2026-66395 | CRITICAL | 9.6 | 0.3% | Jul 27, 2026 | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler... |
| CVE-2026-66394 | CRITICAL | 9.3 | 0.3% | Jul 27, 2026 | SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows ... |
| CVE-2026-16812 | CRITICAL | 10 | 1.0% | Jul 27, 2026 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privile... |
| CVE-2026-59550 | CRITICAL | 9.3 | — | Jul 27, 2026 | Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. |
| CVE-2026-59549 | CRITICAL | 9.3 | — | Jul 27, 2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. |
| CVE-2026-59538 | CRITICAL | 9.3 | — | Jul 27, 2026 | Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. |
| CVE-2026-59533 | CRITICAL | 9.3 | — | Jul 27, 2026 | Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. |
| CVE-2026-59527 | CRITICAL | 9.3 | — | Jul 27, 2026 | Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. |
| CVE-2026-65879 | CRITICAL | 9.8 | 0.1% | Jul 27, 2026 | Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder <... |
| CVE-2026-65876 | CRITICAL | 9.2 | 0.2% | Jul 27, 2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0 - Improper validation of c... |
| CVE-2026-65766 | CRITICAL | 9.2 | — | Jul 27, 2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of o... |
| CVE-2026-61511 | CRITICAL | 9.8 | 1.3% | Jul 27, 2026 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::... |
| CVE-2026-58662 | CRITICAL | 9.1 | — | Jul 27, 2026 | Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. Thi... |
| CVE-2026-58023 | CRITICAL | 9.1 | — | Jul 27, 2026 | Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Us... |
| CVE-2026-55971 | CRITICAL | 9.8 | — | Jul 27, 2026 | Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0... |
| CVE-2026-48144 | CRITICAL | 9.1 | — | Jul 27, 2026 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affect... |
| CVE-2026-64535 | CRITICAL | 9.8 | 0.5% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch S... |
| CVE-2026-64534 | CRITICAL | 9.8 | 0.4% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_unini... |
| CVE-2026-14289 | CRITICAL | 9 | — | Jul 27, 2026 | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request hand... |
| CVE-2026-13714 | CRITICAL | 9.8 | — | Jul 27, 2026 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded f... |
| CVE-2026-13597 | CRITICAL | 9.1 | — | Jul 27, 2026 | The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check alwa... |
| CVE-2026-13332 | CRITICAL | 9.1 | — | Jul 27, 2026 | The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX acti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now