2026 CVE Vulnerabilities
50,995 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9335 | MEDIUM | 6.5 | 0.6% | Aug 2, 2026 | A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp... |
| CVE-2026-8457 | CRITICAL | 9.8 | 0.4% | Aug 2, 2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc... |
| CVE-2026-18352 | HIGH | 7.5 | 0.7% | Aug 2, 2026 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, ... |
| CVE-2026-13339 | HIGH | 7.5 | 0.6% | Aug 2, 2026 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1... |
| CVE-2026-17002 | — | — | — | Aug 1, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-18556 | HIGH | 7.4 | 0.3% | Aug 1, 2026 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.... |
| CVE-2026-55735 | HIGH | 7.5 | 0.2% | Aug 1, 2026 | Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi... |
| CVE-2026-55734 | HIGH | 7.5 | 0.1% | Aug 1, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a... |
| CVE-2026-55733 | HIGH | 7.5 | 0.1% | Aug 1, 2026 | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c... |
| CVE-2026-54894 | HIGH | 7.5 | 0.1% | Aug 1, 2026 | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c... |
| CVE-2026-67355 | HIGH | 8.2 | 0.2% | Aug 1, 2026 | guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain... |
| CVE-2026-67354 | HIGH | 8.2 | 0.3% | Aug 1, 2026 | guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the... |
| CVE-2026-67353 | MEDIUM | 6.9 | 0.2% | Aug 1, 2026 | guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimit... |
| CVE-2026-67352 | HIGH | 7.6 | 0.2% | Aug 1, 2026 | luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows ... |
| CVE-2026-67344 | HIGH | 8.5 | 0.1% | Aug 1, 2026 | ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYP... |
| CVE-2026-67343 | HIGH | 8.8 | 0.3% | Aug 1, 2026 | ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing a... |
| CVE-2026-67342 | CRITICAL | 9.8 | 0.3% | Aug 1, 2026 | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, P... |
| CVE-2026-67341 | CRITICAL | 9.8 | 0.3% | Aug 1, 2026 | ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with... |
| CVE-2026-67340 | HIGH | 7.2 | 0.5% | Aug 1, 2026 | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) b... |
| CVE-2026-67339 | MEDIUM | 6.9 | 0.2% | Aug 1, 2026 | guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR... |
| CVE-2026-67338 | MEDIUM | 6.1 | 0.2% | Aug 1, 2026 | JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to vali... |
| CVE-2026-67337 | HIGH | 7.1 | 0.3% | Aug 1, 2026 | better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is e... |
| CVE-2026-67336 | CRITICAL | 9.4 | 0.2% | Aug 1, 2026 | better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that adve... |
| CVE-2026-67335 | MEDIUM | 6 | 0.2% | Aug 1, 2026 | better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-... |
| CVE-2026-67334 | MEDIUM | 5.1 | 0.2% | Aug 1, 2026 | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now