2026 CVE Vulnerabilities
52,006 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15228 | HIGH | 7.1 | — | Jul 29, 2026 | Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clust... |
| CVE-2026-66724 | MEDIUM | 5.3 | 0.3% | Jul 29, 2026 | MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob u... |
| CVE-2026-66723 | HIGH | 7 | 0.5% | Jul 29, 2026 | MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. ... |
| CVE-2026-65947 | HIGH | 7.3 | 0.1% | Jul 29, 2026 | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 |
| CVE-2026-65888 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows acto... |
| CVE-2026-65887 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method... |
| CVE-2026-65886 | HIGH | 7.5 | 0.4% | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unaut... |
| CVE-2026-59247 | HIGH | 7.6 | 0.1% | Jul 29, 2026 | Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute fo... |
| CVE-2026-54666 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch... |
| CVE-2026-54664 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch... |
| CVE-2026-54663 | MEDIUM | 6.1 | 0.2% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol... |
| CVE-2026-54662 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-... |
| CVE-2026-54661 | HIGH | 8.3 | 0.3% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templat... |
| CVE-2026-54660 | HIGH | 7.4 | 0.2% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol... |
| CVE-2026-12703 | HIGH | 8 | 0.2% | Jul 29, 2026 | TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti... |
| CVE-2026-9177 | CRITICAL | 9.4 | 0.3% | Jul 29, 2026 | A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway Se... |
| CVE-2026-67217 | MEDIUM | 6.9 | 0.2% | Jul 29, 2026 | cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a repl... |
| CVE-2026-67216 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the... |
| CVE-2026-67215 | HIGH | 8.7 | 0.3% | Jul 29, 2026 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON... |
| CVE-2026-67214 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its no... |
| CVE-2026-67213 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these fun... |
| CVE-2026-66490 | MEDIUM | 6.1 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 |
| CVE-2026-66489 | MEDIUM | 5.3 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 |
| CVE-2026-66488 | MEDIUM | 5.3 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 |
| CVE-2026-66400 | MEDIUM | 6.3 | 0.2% | Jul 29, 2026 | Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php wh... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now