2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16349 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115... |
| CVE-2026-65008 | CRITICAL | 9.8 | 0.6% | Jul 21, 2026 | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/... |
| CVE-2026-65007 | CRITICAL | 9.6 | 0.3% | Jul 21, 2026 | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the pl... |
| CVE-2026-1617 | CRITICAL | 9.8 | — | Jul 21, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communica... |
| CVE-2026-64606 | CRITICAL | 9.8 | 0.5% | Jul 21, 2026 | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lamb... |
| CVE-2026-64609 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVa... |
| CVE-2026-64608 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compa... |
| CVE-2026-62415 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membe... |
| CVE-2026-13439 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Admin... |
| CVE-2026-15901 | CRITICAL | 9.6 | 0.3% | Jul 20, 2026 | Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap... |
| CVE-2026-15900 | CRITICAL | 9.6 | 0.3% | Jul 20, 2026 | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perfo... |
| CVE-2026-15899 | CRITICAL | 9.6 | 0.3% | Jul 20, 2026 | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially... |
| CVE-2026-64625 | CRITICAL | 9.8 | 0.4% | Jul 20, 2026 | AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-q... |
| CVE-2026-52656 | CRITICAL | 9.8 | 0.5% | Jul 20, 2026 | An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an a... |
| CVE-2026-53595 | CRITICAL | 9.4 | 0.3% | Jul 20, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public ... |
| CVE-2026-13380 | CRITICAL | 9 | 0.3% | Jul 20, 2026 | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent... |
| CVE-2026-63767 | CRITICAL | 9.8 | 0.7% | Jul 20, 2026 | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability t... |
| CVE-2026-63766 | CRITICAL | 9.8 | 1.4% | Jul 20, 2026 | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, a... |
| CVE-2026-44231 | CRITICAL | 9.1 | 0.2% | Jul 20, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prio... |
| CVE-2026-16337 | CRITICAL | 9.4 | 0.4% | Jul 20, 2026 | Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-... |
| CVE-2026-64193 | CRITICAL | 9.8 | 0.4% | Jul 20, 2026 | Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EX... |
| CVE-2026-62414 | CRITICAL | 9.1 | 0.2% | Jul 20, 2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder ... |
| CVE-2026-61900 | CRITICAL | 10 | 0.3% | Jul 20, 2026 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla exten... |
| CVE-2026-61425 | CRITICAL | 9.4 | 0.3% | Jul 20, 2026 | Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable a... |
| CVE-2026-61424 | CRITICAL | 10 | 0.3% | Jul 20, 2026 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla ext... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now