2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54209 | HIGH | 8.9 | 0.4% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including t... |
| CVE-2026-54208 | HIGH | 8.5 | 0.5% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated... |
| CVE-2026-54204 | HIGH | 7.7 | 0.6% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set t... |
| CVE-2026-54202 | HIGH | 8.5 | 0.3% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation funct... |
| CVE-2026-54200 | HIGH | 8.4 | 0.2% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax,... |
| CVE-2026-12070 | HIGH | 8.4 | 0.2% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, ... |
| CVE-2026-9169 | HIGH | 8.8 | 0.1% | Aug 7, 2026 | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitr... |
| CVE-2026-66491 | HIGH | 8.2 | 0.3% | Aug 7, 2026 | Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the g... |
| CVE-2026-49007 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for th... |
| CVE-2026-19196 | HIGH | 7.3 | 0.3% | Aug 7, 2026 | A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the ... |
| CVE-2026-16263 | HIGH | 8.8 | 0.3% | Aug 7, 2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not p... |
| CVE-2026-16262 | HIGH | 7.5 | 0.1% | Aug 7, 2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating... |
| CVE-2026-16041 | HIGH | 7.5 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p... |
| CVE-2026-16030 | HIGH | 8.1 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t... |
| CVE-2026-15361 | HIGH | 8.1 | 0.2% | Aug 7, 2026 | The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n... |
| CVE-2026-15215 | HIGH | 8.8 | 0.2% | Aug 7, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing ... |
| CVE-2026-14943 | HIGH | 7.5 | 0.1% | Aug 7, 2026 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d... |
| CVE-2026-19195 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in th... |
| CVE-2026-19193 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys... |
| CVE-2026-19192 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C... |
| CVE-2026-19191 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code o... |
| CVE-2026-19190 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Fil... |
| CVE-2026-49746 | HIGH | 7.1 | 0.1% | Aug 7, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memor... |
| CVE-2026-45198 | HIGH | 7.8 | 0.2% | Aug 7, 2026 | Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause G... |
| CVE-2026-19189 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functional... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now