2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59641 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This iss... |
| CVE-2026-59640 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue ... |
| CVE-2026-59639 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue al... |
| CVE-2026-12185 | HIGH | 7.1 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This i... |
| CVE-2026-3245 | HIGH | 7.7 | 0.2% | Aug 3, 2026 | A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. |
| CVE-2026-18577 | HIGH | 8.1 | 2.5% | Aug 2, 2026 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu... |
| CVE-2026-10848 | HIGH | 8.6 | 0.2% | Aug 2, 2026 | The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j... |
| CVE-2026-9856 | HIGH | 7.1 | 0.3% | Aug 2, 2026 | A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes vi... |
| CVE-2026-68581 | HIGH | 8.6 | 0.3% | Aug 2, 2026 | Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and ... |
| CVE-2026-68580 | HIGH | 7.7 | 0.2% | Aug 2, 2026 | FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across AL... |
| CVE-2026-68578 | HIGH | 7.7 | 0.2% | Aug 2, 2026 | ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine p... |
| CVE-2026-67357 | HIGH | 7.7 | 0.3% | Aug 2, 2026 | ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that... |
| CVE-2026-67356 | HIGH | 8.8 | 0.2% | Aug 2, 2026 | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowin... |
| CVE-2026-18571 | HIGH | 7.2 | 0.2% | Aug 2, 2026 | A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled.... |
| CVE-2026-16540 | HIGH | 7.5 | 0.2% | Aug 2, 2026 | The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati... |
| CVE-2026-16285 | HIGH | 7.5 | 0.1% | Aug 2, 2026 | The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before str... |
| CVE-2026-16261 | HIGH | 7.5 | 0.2% | Aug 2, 2026 | The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the req... |
| CVE-2026-15241 | HIGH | 7.5 | 0.1% | Aug 2, 2026 | The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one o... |
| CVE-2026-15236 | HIGH | 7.5 | 0.2% | Aug 2, 2026 | The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party... |
| CVE-2026-15206 | HIGH | 7.5 | 0.1% | Aug 2, 2026 | The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that w... |
| CVE-2026-15151 | HIGH | 7.5 | 0.1% | Aug 2, 2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its ... |
| CVE-2026-14920 | HIGH | 8.2 | 0.2% | Aug 2, 2026 | ## Summary |
| CVE-2026-12586 | HIGH | 8.1 | 0.1% | Aug 2, 2026 | The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset... |
| CVE-2026-18352 | HIGH | 7.5 | 0.7% | Aug 2, 2026 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, ... |
| CVE-2026-13339 | HIGH | 7.5 | 0.6% | Aug 2, 2026 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now