2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52439 | CRITICAL | 9.8 | 0.5% | Jul 23, 2026 | An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the p... |
| CVE-2026-49035 | CRITICAL | 9.2 | 0.4% | Jul 23, 2026 | The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execu... |
| CVE-2026-47724 | CRITICAL | 9.9 | 0.4% | Jul 23, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/... |
| CVE-2026-15981 | CRITICAL | 9.8 | 0.5% | Jul 23, 2026 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, a... |
| CVE-2026-15967 | CRITICAL | 9.8 | 0.2% | Jul 23, 2026 | Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2... |
| CVE-2026-15966 | CRITICAL | 9.8 | 0.2% | Jul 23, 2026 | Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue af... |
| CVE-2026-15630 | CRITICAL | 9.9 | 0.2% | Jul 23, 2026 | A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any... |
| CVE-2026-10697 | CRITICAL | 9.8 | 0.2% | Jul 23, 2026 | Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5,... |
| CVE-2026-63359 | CRITICAL | 9.8 | 0.4% | Jul 23, 2026 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated att... |
| CVE-2026-47670 | CRITICAL | 9.4 | 1.7% | Jul 23, 2026 | DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Executio... |
| CVE-2026-47669 | CRITICAL | 9.3 | 0.3% | Jul 23, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api... |
| CVE-2026-6516 | CRITICAL | 10 | — | Jul 23, 2026 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the... |
| CVE-2026-65701 | CRITICAL | 9.3 | — | Jul 23, 2026 | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inf... |
| CVE-2026-65700 | CRITICAL | 9.8 | 1.3% | Jul 23, 2026 | h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica... |
| CVE-2026-47752 | CRITICAL | 9.9 | — | Jul 23, 2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to S... |
| CVE-2026-47668 | CRITICAL | 10 | — | Jul 23, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/star... |
| CVE-2026-44210 | CRITICAL | 9.9 | 0.3% | Jul 23, 2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2026-65761 | CRITICAL | 9.3 | — | Jul 23, 2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validat... |
| CVE-2026-65760 | CRITICAL | 9.2 | — | Jul 23, 2026 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0... |
| CVE-2026-15617 | CRITICAL | 9.1 | 0.2% | Jul 23, 2026 | Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unaut... |
| CVE-2026-15616 | CRITICAL | 9.1 | 0.2% | Jul 23, 2026 | Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirem... |
| CVE-2026-15612 | CRITICAL | 9.1 | 0.1% | Jul 23, 2026 | Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication... |
| CVE-2026-15611 | CRITICAL | 9.1 | 0.2% | Jul 23, 2026 | Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive Id... |
| CVE-2026-65689 | CRITICAL | 9.8 | 0.6% | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its datab... |
| CVE-2026-65688 | CRITICAL | 9.8 | 0.6% | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now