2026 CVE Vulnerabilities
51,076 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62845 | MEDIUM | 4.7 | — | Jul 30, 2026 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv... |
| CVE-2026-62246 | HIGH | 8.5 | 0.3% | Jul 30, 2026 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane dat... |
| CVE-2026-5846 | HIGH | 7.6 | 0.2% | Jul 30, 2026 | The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 cert... |
| CVE-2026-38709 | CRITICAL | 9.8 | — | Jul 30, 2026 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2... |
| CVE-2026-18064 | HIGH | 8.2 | 0.3% | Jul 30, 2026 | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a s... |
| CVE-2026-12562 | HIGH | 8.8 | 0.3% | Jul 30, 2026 | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full... |
| CVE-2026-68503 | CRITICAL | 9.8 | 0.4% | Jul 30, 2026 | LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships def... |
| CVE-2026-68502 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.... |
| CVE-2026-68501 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli... |
| CVE-2026-68500 | HIGH | 7.5 | 0.4% | Jul 30, 2026 | Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli... |
| CVE-2026-68499 | MEDIUM | 6.2 | 0.1% | Jul 30, 2026 | re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match ... |
| CVE-2026-66803 | CRITICAL | 10 | 0.5% | Jul 30, 2026 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66418 | CRITICAL | 9.3 | 0.3% | Jul 30, 2026 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attack... |
| CVE-2026-61526 | MEDIUM | 6.1 | 0.2% | Jul 30, 2026 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through... |
| CVE-2026-55777 | MEDIUM | 5.3 | — | Jul 30, 2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b... |
| CVE-2026-55768 | HIGH | 8.7 | 0.3% | Jul 30, 2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b... |
| CVE-2026-54715 | HIGH | 7.1 | 0.3% | Jul 30, 2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b... |
| CVE-2026-52539 | CRITICAL | 9.1 | — | Jul 30, 2026 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not se... |
| CVE-2026-35847 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the Chec... |
| CVE-2026-67594 | CRITICAL | 9.8 | 0.5% | Jul 30, 2026 | Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attac... |
| CVE-2026-67550 | MEDIUM | 5.7 | 0.1% | Jul 30, 2026 | re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex again... |
| CVE-2026-67530 | MEDIUM | 6.4 | 0.2% | Jul 30, 2026 | WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/... |
| CVE-2026-67529 | MEDIUM | 4.3 | 0.2% | Jul 30, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /ap... |
| CVE-2026-67528 | MEDIUM | 4.3 | 0.2% | Jul 30, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resol... |
| CVE-2026-67527 | HIGH | 7.6 | 0.2% | Jul 30, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} acc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now