2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45695 | CRITICAL | 9.8 | — | Jul 16, 2026 | Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-en... |
| CVE-2026-14890 | CRITICAL | 9.1 | 0.9% | Jul 16, 2026 | SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that d... |
| CVE-2026-56453 | CRITICAL | 9.8 | 0.2% | Jul 16, 2026 | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter... |
| CVE-2026-63306 | CRITICAL | 9.2 | — | Jul 16, 2026 | stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed e... |
| CVE-2026-63305 | CRITICAL | 9.2 | 1.4% | Jul 16, 2026 | AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and ... |
| CVE-2026-63304 | CRITICAL | 9.2 | 1.4% | Jul 16, 2026 | AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the list... |
| CVE-2026-11386 | CRITICAL | 9 | — | Jul 16, 2026 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools).... |
| CVE-2026-22752 | CRITICAL | 9.6 | 0.4% | Jul 16, 2026 | Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affe... |
| CVE-2026-15925 | CRITICAL | 9.2 | 0.2% | Jul 16, 2026 | Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed... |
| CVE-2026-12492 | CRITICAL | 9.8 | 0.1% | Jul 16, 2026 | The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actu... |
| CVE-2026-15013 | CRITICAL | 9.8 | 0.4% | Jul 16, 2026 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algor... |
| CVE-2026-55652 | CRITICAL | 9.8 | 0.4% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequest... |
| CVE-2026-55445 | CRITICAL | 9.3 | 0.4% | Jul 15, 2026 | Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the... |
| CVE-2026-54458 | CRITICAL | 9.6 | 0.3% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerabi... |
| CVE-2026-52893 | CRITICAL | 9.2 | 0.3% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/user... |
| CVE-2026-52891 | CRITICAL | 9.9 | 0.4% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied fil... |
| CVE-2026-30623 | CRITICAL | 9.8 | 0.3% | Jul 15, 2026 | LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application... |
| CVE-2026-30618 | CRITICAL | 9.8 | 0.6% | Jul 15, 2026 | xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution... |
| CVE-2026-26718 | CRITICAL | 9.1 | 0.3% | Jul 15, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att... |
| CVE-2026-54052 | CRITICAL | 9.9 | 0.4% | Jul 15, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-52887 | CRITICAL | 10 | 0.6% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-51380 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of S... |
| CVE-2026-49352 | CRITICAL | 9.8 | 0.6% | Jul 15, 2026 | 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-... |
| CVE-2026-46339 | CRITICAL | 10 | 4.6% | Jul 15, 2026 | 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/... |
| CVE-2026-46684 | CRITICAL | 9.5 | 0.2% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling ca... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now