2026 CVE Vulnerabilities
47,701 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7831 | HIGH | 7.6 | 0.4% | Jul 1, 2026 | UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In v... |
| CVE-2026-7830 | HIGH | 7.4 | 0.2% | Jul 1, 2026 | UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAut... |
| CVE-2026-7829 | HIGH | 7.2 | 0.5% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In r... |
| CVE-2026-7517 | HIGH | 7.2 | 0.2% | Jul 1, 2026 | The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a... |
| CVE-2026-13731 | HIGH | 7.2 | 0.2% | Jul 1, 2026 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2026-13468 | HIGH | 7.5 | 0.4% | Jul 1, 2026 | The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization ... |
| CVE-2026-12923 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3... |
| CVE-2026-20458 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of p... |
| CVE-2026-14191 | HIGH | 7.8 | 0.3% | Jul 1, 2026 | An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeade... |
| CVE-2026-53488 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plu... |
| CVE-2026-54592 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj::Doc#... |
| CVE-2026-57995 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GR... |
| CVE-2026-56361 | HIGH | 7.1 | 0.1% | Jun 30, 2026 | ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer rea... |
| CVE-2026-56350 | HIGH | 7.7 | 0.3% | Jun 30, 2026 | n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforce... |
| CVE-2026-56328 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unn... |
| CVE-2026-56320 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_i... |
| CVE-2026-56300 | HIGH | 8.7 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey th... |
| CVE-2026-56286 | HIGH | 8.1 | 0.4% | Jun 30, 2026 | Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows delet... |
| CVE-2026-56249 | HIGH | 7.6 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authen... |
| CVE-2026-56247 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compa... |
| CVE-2026-56233 | HIGH | 8.7 | 0.5% | Jun 30, 2026 | Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated user... |
| CVE-2026-56230 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the cli... |
| CVE-2026-56219 | HIGH | 8.7 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac function that all... |
| CVE-2026-54673 | HIGH | 8.2 | 0.2% | Jun 30, 2026 | electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor... |
| CVE-2026-54672 | HIGH | 7.8 | 0.1% | Jun 30, 2026 | electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now