2026 CVE Vulnerabilities
51,054 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51231 | — | — | — | Jul 31, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51230 | — | — | — | Jul 31, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-51229 | — | — | — | Jul 31, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-18446 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a refer... |
| CVE-2026-10685 | HIGH | 7.6 | 0.2% | Jul 31, 2026 | The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked... |
| CVE-2026-65636 | LOW | 2.1 | 0.1% | Jul 31, 2026 | Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inj... |
| CVE-2026-28145 | MEDIUM | 5.3 | 0.1% | Jul 31, 2026 | Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User ... |
| CVE-2026-28144 | MEDIUM | 4.3 | 0.2% | Jul 31, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensiti... |
| CVE-2026-9611 | — | — | — | Jul 31, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-68577 | — | — | — | Jul 31, 2026 | Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly res... |
| CVE-2026-68576 | — | — | — | Jul 31, 2026 | Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly res... |
| CVE-2026-68575 | — | — | — | Jul 31, 2026 | Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly res... |
| CVE-2026-68574 | — | — | — | Jul 31, 2026 | Rejected reason: Reserved via standalone CLI outside the OSIM flaw workflow; releasing so the CVE ID can be properly res... |
| CVE-2026-18358 | HIGH | 7.5 | 0.4% | Jul 31, 2026 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mo... |
| CVE-2026-17592 | — | — | — | Jul 31, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-17561 | CRITICAL | 9.8 | 0.3% | Jul 31, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Cons... |
| CVE-2026-15227 | MEDIUM | 5.3 | 0.2% | Jul 31, 2026 | Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking t... |
| CVE-2026-46594 | MEDIUM | 5.1 | 0.3% | Jul 31, 2026 | A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicio... |
| CVE-2026-46593 | HIGH | 8.6 | 0.3% | Jul 31, 2026 | A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input... |
| CVE-2026-64607 | MEDIUM | 5.3 | 0.3% | Jul 31, 2026 | HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma... |
| CVE-2026-62391 | HIGH | 8.1 | 0.4% | Jul 31, 2026 | The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend... |
| CVE-2026-44615 | MEDIUM | 6.5 | 0.5% | Jul 31, 2026 | Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi... |
| CVE-2026-17567 | MEDIUM | 5.3 | 0.4% | Jul 31, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2026-16843 | HIGH | 7.2 | 0.5% | Jul 31, 2026 | Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio... |
| CVE-2026-18437 | MEDIUM | 5.3 | 0.3% | Jul 31, 2026 | The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now