2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51536 | CRITICAL | 9.1 | 0.5% | Jul 13, 2026 | In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length para... |
| CVE-2026-58409 | CRITICAL | 9.1 | 0.5% | Jul 13, 2026 | ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve... |
| CVE-2026-6875 | CRITICAL | 9.5 | — | Jul 13, 2026 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This v... |
| CVE-2026-61500 | CRITICAL | 9.8 | 0.7% | Jul 13, 2026 | Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generato... |
| CVE-2026-61462 | CRITICAL | 9.2 | — | Jul 13, 2026 | mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to re... |
| CVE-2026-57433 | CRITICAL | 9.8 | 0.2% | Jul 13, 2026 | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retr... |
| CVE-2026-13221 | CRITICAL | 9.1 | 0.2% | Jul 13, 2026 | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 6553... |
| CVE-2026-6847 | CRITICAL | 9.3 | 0.6% | Jul 13, 2026 | Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload fu... |
| CVE-2026-61498 | CRITICAL | 9.8 | 2.2% | Jul 13, 2026 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php en... |
| CVE-2026-60121 | CRITICAL | 9.8 | — | Jul 13, 2026 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint... |
| CVE-2026-40469 | CRITICAL | 9.1 | — | Jul 13, 2026 | Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could b... |
| CVE-2026-40468 | CRITICAL | 9.1 | — | Jul 13, 2026 | Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaust... |
| CVE-2026-12257 | CRITICAL | 9.3 | — | Jul 13, 2026 | Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located... |
| CVE-2026-14934 | CRITICAL | 9.4 | — | Jul 13, 2026 | A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Co... |
| CVE-2026-59518 | CRITICAL | 9.8 | 0.6% | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affe... |
| CVE-2026-59515 | CRITICAL | 9.3 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-cop... |
| CVE-2026-57813 | CRITICAL | 9.8 | 0.5% | Jul 13, 2026 | Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issu... |
| CVE-2026-57811 | CRITICAL | 10 | 0.6% | Jul 13, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-est... |
| CVE-2026-57770 | CRITICAL | 9.8 | 0.6% | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection... |
| CVE-2026-57744 | CRITICAL | 9.8 | 0.6% | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injecti... |
| CVE-2026-57739 | CRITICAL | 9.3 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newslet... |
| CVE-2026-57738 | CRITICAL | 9.8 | 0.6% | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affec... |
| CVE-2026-57726 | CRITICAL | 9.3 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirk... |
| CVE-2026-57724 | CRITICAL | 9.8 | 0.6% | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki:... |
| CVE-2026-57719 | CRITICAL | 10 | 0.5% | Jul 13, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Mal... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now