2026 CVE Vulnerabilities
50,985 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10774 | MEDIUM | 6.5 | 0.2% | Aug 2, 2026 | Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/blue... |
| CVE-2026-68583 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th... |
| CVE-2026-68582 | CRITICAL | 9.3 | 0.2% | Aug 2, 2026 | Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-col... |
| CVE-2026-68581 | HIGH | 8.6 | 0.3% | Aug 2, 2026 | Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and ... |
| CVE-2026-68580 | HIGH | 7.7 | 0.2% | Aug 2, 2026 | FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across AL... |
| CVE-2026-68579 | CRITICAL | 9.6 | 0.3% | Aug 2, 2026 | FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_... |
| CVE-2026-68578 | HIGH | 7.7 | 0.2% | Aug 2, 2026 | ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine p... |
| CVE-2026-67357 | HIGH | 7.7 | 0.3% | Aug 2, 2026 | ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that... |
| CVE-2026-67356 | HIGH | 8.8 | 0.2% | Aug 2, 2026 | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowin... |
| CVE-2026-12231 | MEDIUM | 6.4 | 0.3% | Aug 2, 2026 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_info... |
| CVE-2026-18573 | MEDIUM | 6.5 | 0.2% | Aug 2, 2026 | A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza... |
| CVE-2026-18572 | MEDIUM | 6.5 | 0.2% | Aug 2, 2026 | Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie... |
| CVE-2026-18571 | HIGH | 7.2 | 0.2% | Aug 2, 2026 | A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled.... |
| CVE-2026-18570 | MEDIUM | 5.4 | 0.2% | Aug 2, 2026 | A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen... |
| CVE-2026-16540 | HIGH | 7.5 | 0.4% | Aug 2, 2026 | The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati... |
| CVE-2026-16292 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta... |
| CVE-2026-16291 | MEDIUM | 4.3 | 0.2% | Aug 2, 2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo... |
| CVE-2026-16285 | HIGH | 7.5 | 0.3% | Aug 2, 2026 | The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before str... |
| CVE-2026-16273 | MEDIUM | 4.6 | 0.1% | Aug 2, 2026 | The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field ... |
| CVE-2026-16261 | HIGH | 7.5 | 0.3% | Aug 2, 2026 | The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the req... |
| CVE-2026-16256 | CRITICAL | 9.8 | 0.3% | Aug 2, 2026 | The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions av... |
| CVE-2026-16064 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the o... |
| CVE-2026-16063 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont... |
| CVE-2026-16062 | MEDIUM | 6.6 | 0.3% | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co... |
| CVE-2026-16042 | MEDIUM | 4.3 | 0.2% | Aug 2, 2026 | The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now