2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71226 | HIGH | 7.3 | 0.1% | Aug 5, 2026 | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all subm... |
| CVE-2026-16022 | HIGH | 7.8 | — | Aug 5, 2026 | @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constr... |
| CVE-2026-71255 | HIGH | 8.6 | 0.2% | Aug 5, 2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res... |
| CVE-2026-64582 | HIGH | 7.8 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap ... |
| CVE-2026-61891 | HIGH | 7.5 | 0.5% | Aug 5, 2026 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoin... |
| CVE-2026-46581 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or ... |
| CVE-2026-18933 | HIGH | 7.2 | 0.4% | Aug 5, 2026 | The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-pri... |
| CVE-2026-71252 | HIGH | 8.2 | 0.4% | Aug 5, 2026 | toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, ... |
| CVE-2026-71245 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the reques... |
| CVE-2026-71243 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, dest... |
| CVE-2026-71242 | HIGH | 8.3 | 0.2% | Aug 5, 2026 | Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership ... |
| CVE-2026-71241 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are mi... |
| CVE-2026-71239 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template const... |
| CVE-2026-71236 | HIGH | 8.7 | 0.2% | Aug 5, 2026 | Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incomi... |
| CVE-2026-71235 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-sid... |
| CVE-2026-71234 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPubl... |
| CVE-2026-71233 | HIGH | 8.7 | 0.2% | Aug 5, 2026 | InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output... |
| CVE-2026-71232 | HIGH | 7.2 | 0.5% | Aug 5, 2026 | MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template ... |
| CVE-2026-60009 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every... |
| CVE-2026-12609 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlug... |
| CVE-2026-25703 | HIGH | 7.3 | — | Aug 5, 2026 | NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authenticatio... |
| CVE-2026-7693 | HIGH | 7.2 | 2.2% | Aug 5, 2026 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.... |
| CVE-2026-7520 | HIGH | 8.1 | 0.3% | Aug 5, 2026 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2026-7444 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2026-71215 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and ext... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now