2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67335 | MEDIUM | 6 | 0.2% | Aug 1, 2026 | better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-... |
| CVE-2026-67334 | MEDIUM | 5.1 | 0.2% | Aug 1, 2026 | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp... |
| CVE-2026-67332 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing... |
| CVE-2026-67321 | MEDIUM | 6.9 | 0.3% | Aug 1, 2026 | axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js w... |
| CVE-2026-67319 | MEDIUM | 6.3 | 0.3% | Aug 1, 2026 | axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the... |
| CVE-2026-67318 | MEDIUM | 6.3 | 0.4% | Aug 1, 2026 | axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bo... |
| CVE-2026-67317 | MEDIUM | 6.3 | 0.4% | Aug 1, 2026 | axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch a... |
| CVE-2026-67316 | MEDIUM | 6.3 | 0.3% | Aug 1, 2026 | axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype h... |
| CVE-2026-67315 | MEDIUM | 6.9 | 0.3% | Aug 1, 2026 | axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBy... |
| CVE-2026-67314 | MEDIUM | 6.3 | 0.4% | Aug 1, 2026 | axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/a... |
| CVE-2026-67313 | MEDIUM | 6.3 | 0.3% | Aug 1, 2026 | axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names wi... |
| CVE-2026-67312 | MEDIUM | 6.3 | 0.3% | Aug 1, 2026 | axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (... |
| CVE-2026-67310 | MEDIUM | 5.4 | 0.2% | Aug 1, 2026 | OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in t... |
| CVE-2026-67306 | MEDIUM | 5.4 | 0.3% | Aug 1, 2026 | FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder fu... |
| CVE-2026-67303 | MEDIUM | 5.3 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a reachable assertion (WINPR_ASSERT(OutputBufferLength == BytesReturned)) in serial_proce... |
| CVE-2026-67302 | MEDIUM | 5.3 | 0.3% | Aug 1, 2026 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redire... |
| CVE-2026-67295 | MEDIUM | 6.3 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to... |
| CVE-2026-2411 | MEDIUM | 6.5 | 0.1% | Aug 1, 2026 | Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose... |
| CVE-2026-10773 | MEDIUM | 5.4 | 0.2% | Aug 1, 2026 | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const c... |
| CVE-2026-6453 | MEDIUM | 6.5 | 0.3% | Aug 1, 2026 | The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi... |
| CVE-2026-18435 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-18344 | MEDIUM | 6.1 | 0.2% | Aug 1, 2026 | The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par... |
| CVE-2026-18062 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-18059 | MEDIUM | 5.3 | 0.3% | Aug 1, 2026 | The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp... |
| CVE-2026-17605 | MEDIUM | 6.6 | 0.7% | Aug 1, 2026 | The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Incl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now