2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10755 | LOW | 2.7 | 0.2% | Jul 20, 2026 | The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST ... |
| CVE-2026-16218 | LOW | 2.6 | 0.2% | Jul 19, 2026 | A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the function reset_storage of th... |
| CVE-2026-16211 | LOW | 2.6 | 0.2% | Jul 19, 2026 | A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function Asse... |
| CVE-2026-16205 | LOW | 2.4 | 0.2% | Jul 19, 2026 | A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decod... |
| CVE-2026-16203 | LOW | 3.5 | 0.2% | Jul 19, 2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u... |
| CVE-2026-16202 | LOW | 3.5 | 0.2% | Jul 19, 2026 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i... |
| CVE-2026-16156 | LOW | 3.5 | 0.2% | Jul 18, 2026 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown par... |
| CVE-2026-16155 | LOW | 3.5 | 0.2% | Jul 18, 2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u... |
| CVE-2026-54335 | LOW | 3.7 | 0.4% | Jul 17, 2026 | Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and ... |
| CVE-2026-54244 | LOW | 3.5 | 0.3% | Jul 17, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp... |
| CVE-2026-48978 | LOW | 2.1 | 0.3% | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's ... |
| CVE-2026-50185 | LOW | 3.3 | 0.1% | Jul 17, 2026 | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-... |
| CVE-2026-16073 | LOW | 3.5 | 0.2% | Jul 17, 2026 | A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S... |
| CVE-2026-15997 | LOW | 1.7 | 0.1% | Jul 16, 2026 | Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffer... |
| CVE-2026-62994 | LOW | 3.7 | 0.3% | Jul 16, 2026 | CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreD... |
| CVE-2026-47088 | LOW | 3.1 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi... |
| CVE-2026-47087 | LOW | 3.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A... |
| CVE-2026-47086 | LOW | 3.5 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe... |
| CVE-2026-47081 | LOW | 3.1 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac... |
| CVE-2026-44969 | LOW | 3.3 | 0.1% | Jul 16, 2026 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/... |
| CVE-2026-15945 | LOW | 2.7 | 0.3% | Jul 16, 2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin ... |
| CVE-2026-35145 | LOW | 3.1 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to ... |
| CVE-2026-12907 | LOW | 2.7 | 0.1% | Jul 16, 2026 | The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions,... |
| CVE-2026-12906 | LOW | 2.7 | 0.1% | Jul 16, 2026 | The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a r... |
| CVE-2026-38755 | LOW | 2.9 | 0.3% | Jul 15, 2026 | A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Ser... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now