2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16572 | HIGH | 8.6 | 0.2% | Aug 3, 2026 | The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a... |
| CVE-2026-16539 | HIGH | 8.1 | 0.2% | Aug 3, 2026 | The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a S... |
| CVE-2026-14682 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This i... |
| CVE-2026-13506 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects B... |
| CVE-2026-12860 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issu... |
| CVE-2026-12852 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check. |
| CVE-2026-12817 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also af... |
| CVE-2026-12816 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also... |
| CVE-2026-12803 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forg... |
| CVE-2026-12802 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also ... |
| CVE-2026-58061 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue al... |
| CVE-2026-58060 | HIGH | 8.7 | 0.4% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This is... |
| CVE-2026-58059 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue a... |
| CVE-2026-20495 | HIGH | 7.8 | 0.1% | Aug 3, 2026 | In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local e... |
| CVE-2026-20483 | HIGH | 7.7 | 0.1% | Aug 3, 2026 | In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local es... |
| CVE-2026-20479 | HIGH | 7.5 | 0.2% | Aug 3, 2026 | In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv... |
| CVE-2026-20465 | HIGH | 8.1 | 0.2% | Aug 3, 2026 | In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (pro... |
| CVE-2026-65875 | HIGH | 7.1 | 0.2% | Aug 3, 2026 | BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens... |
| CVE-2026-59651 | HIGH | 7.1 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue als... |
| CVE-2026-59649 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory. This issu... |
| CVE-2026-59646 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This is... |
| CVE-2026-59645 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. T... |
| CVE-2026-59644 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender. |
| CVE-2026-59643 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affect... |
| CVE-2026-59642 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now