2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63030 | CRITICAL | 9.8 | 38.6% | Jul 17, 2026 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which... |
| CVE-2026-52199 | CRITICAL | 9.1 | 0.6% | Jul 17, 2026 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/... |
| CVE-2026-42168 | CRITICAL | 9.1 | 1.2% | Jul 17, 2026 | django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner ... |
| CVE-2026-36669 | CRITICAL | 9.8 | 0.6% | Jul 17, 2026 | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote ... |
| CVE-2026-15091 | CRITICAL | 9.3 | 0.3% | Jul 17, 2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to imprope... |
| CVE-2026-14501 | CRITICAL | 9.8 | 0.2% | Jul 17, 2026 | IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain se... |
| CVE-2026-13473 | CRITICAL | 9.8 | 0.5% | Jul 17, 2026 | IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner... |
| CVE-2026-13448 | CRITICAL | 9.8 | 0.5% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the... |
| CVE-2026-9135 | CRITICAL | 9.9 | 0.8% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) co... |
| CVE-2026-9103 | CRITICAL | 9.8 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authenti... |
| CVE-2026-9202 | CRITICAL | 9.8 | 0.3% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow... |
| CVE-2026-9198 | CRITICAL | 9.8 | 1.9% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER toke... |
| CVE-2026-9586 | CRITICAL | 9.3 | 0.4% | Jul 17, 2026 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint pr... |
| CVE-2026-8297 | CRITICAL | 9.8 | — | Jul 17, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics En... |
| CVE-2026-54496 | CRITICAL | 9.3 | — | Jul 17, 2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primit... |
| CVE-2026-12694 | CRITICAL | 9.1 | — | Jul 17, 2026 | Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Proper... |
| CVE-2026-12693 | CRITICAL | 9.4 | — | Jul 17, 2026 | Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessi... |
| CVE-2026-12692 | CRITICAL | 9.8 | — | Jul 17, 2026 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This ... |
| CVE-2026-60024 | CRITICAL | 9.8 | 0.3% | Jul 17, 2026 | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Event... |
| CVE-2026-51080 | CRITICAL | 9.8 | 0.3% | Jul 17, 2026 | libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnera... |
| CVE-2026-9810 | CRITICAL | 9.8 | 0.1% | Jul 17, 2026 | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any val... |
| CVE-2026-15982 | CRITICAL | 9.8 | 0.3% | Jul 17, 2026 | The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable ... |
| CVE-2026-62241 | CRITICAL | 9.3 | 0.4% | Jul 17, 2026 | clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me')... |
| CVE-2026-62232 | CRITICAL | 9.1 | 0.3% | Jul 17, 2026 | Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FAS... |
| CVE-2026-14956 | CRITICAL | 9.8 | 0.4% | Jul 17, 2026 | The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now