2026 CVE Vulnerabilities
52,737 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50735 | MEDIUM | 6.8 | 0.2% | Jul 28, 2026 | pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol me... |
| CVE-2026-4932 | MEDIUM | 4.2 | — | Jul 28, 2026 | IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physica... |
| CVE-2026-4912 | MEDIUM | 4.1 | — | Jul 28, 2026 | The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio... |
| CVE-2026-49258 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*... |
| CVE-2026-48396 | HIGH | 8.6 | 0.2% | Jul 28, 2026 | Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the cont... |
| CVE-2026-48395 | HIGH | 8.6 | 0.2% | Jul 28, 2026 | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex... |
| CVE-2026-48394 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ... |
| CVE-2026-48393 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ... |
| CVE-2026-48392 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ... |
| CVE-2026-48391 | HIGH | 8.2 | 0.2% | Jul 28, 2026 | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex... |
| CVE-2026-48390 | HIGH | 8.2 | 0.1% | Jul 28, 2026 | Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker co... |
| CVE-2026-48374 | HIGH | 7.8 | 0.2% | Jul 28, 2026 | Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability th... |
| CVE-2026-48058 | MEDIUM | 4.6 | 0.2% | Jul 28, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern... |
| CVE-2026-47768 | MEDIUM | 5.5 | 0.1% | Jul 28, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-... |
| CVE-2026-47726 | HIGH | 7.1 | 0.2% | Jul 28, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern... |
| CVE-2026-47725 | MEDIUM | 6.9 | 0.2% | Jul 28, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every ... |
| CVE-2026-18107 | HIGH | 7.8 | 0.1% | Jul 28, 2026 | A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insid... |
| CVE-2026-16771 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on ... |
| CVE-2026-16498 | CRITICAL | 10 | 0.3% | Jul 28, 2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-H... |
| CVE-2026-16496 | HIGH | 8.9 | 0.3% | Jul 28, 2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful t... |
| CVE-2026-15992 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.... |
| CVE-2026-15304 | MEDIUM | 6.5 | — | Jul 28, 2026 | The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions ... |
| CVE-2026-14869 | HIGH | 8.6 | 0.3% | Jul 28, 2026 | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTT... |
| CVE-2026-59933 | HIGH | 7.5 | 0.7% | Jul 28, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t... |
| CVE-2026-59931 | HIGH | 7.7 | 0.5% | Jul 28, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now