2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64874 | CRITICAL | 9.8 | 0.1% | Jul 23, 2026 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed i... |
| CVE-2026-64873 | CRITICAL | 9.8 | 0.1% | Jul 23, 2026 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or re... |
| CVE-2026-15015 | CRITICAL | 9.8 | — | Jul 23, 2026 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u... |
| CVE-2026-15011 | CRITICAL | 9.8 | 1.0% | Jul 23, 2026 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame... |
| CVE-2026-14282 | CRITICAL | 9.8 | 1.3% | Jul 23, 2026 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for ... |
| CVE-2026-16723 | CRITICAL | 9 | 0.7% | Jul 23, 2026 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable ... |
| CVE-2026-60372 | CRITICAL | 9.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60369 | CRITICAL | 9.9 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60367 | CRITICAL | 9.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60366 | CRITICAL | 10 | 0.5% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-64798 | CRITICAL | 9.1 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also... |
| CVE-2026-64796 | CRITICAL | 9.8 | 0.2% | Jul 22, 2026 | Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both t... |
| CVE-2026-64793 | CRITICAL | 9.1 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere ext... |
| CVE-2026-64829 | CRITICAL | 9.1 | 0.3% | Jul 22, 2026 | Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obta... |
| CVE-2026-13072 | CRITICAL | 9.2 | 0.4% | Jul 22, 2026 | When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data du... |
| CVE-2026-16624 | CRITICAL | 9.6 | 0.2% | Jul 22, 2026 | Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on... |
| CVE-2026-16606 | CRITICAL | 9.8 | — | Jul 22, 2026 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allow... |
| CVE-2026-2395 | CRITICAL | 9.8 | 0.4% | Jul 22, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Info... |
| CVE-2026-62144 | CRITICAL | 9.1 | 1.0% | Jul 22, 2026 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an... |
| CVE-2026-50252 | CRITICAL | 9.3 | 0.1% | Jul 22, 2026 | In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret... |
| CVE-2026-16232 | CRITICAL | 9.8 | 71.4% | Jul 22, 2026 | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote at... |
| CVE-2026-8152 | CRITICAL | 9.3 | — | Jul 22, 2026 | Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) atta... |
| CVE-2026-65590 | CRITICAL | 9.8 | 0.3% | Jul 22, 2026 | n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/... |
| CVE-2026-63048 | CRITICAL | 9.4 | 0.2% | Jul 22, 2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder ... |
| CVE-2026-56820 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now