2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11383 | MEDIUM | 5.4 | — | Jul 30, 2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scri... |
| CVE-2026-58218 | MEDIUM | 5.3 | — | Jul 30, 2026 | A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY ... |
| CVE-2026-54364 | MEDIUM | 6.9 | — | Jul 30, 2026 | CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inj... |
| CVE-2026-7260 | MEDIUM | 5.5 | 0.2% | Jul 30, 2026 | Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP ... |
| CVE-2026-5582 | MEDIUM | 4.3 | 0.1% | Jul 30, 2026 | The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24... |
| CVE-2026-18382 | MEDIUM | 6.8 | 0.3% | Jul 30, 2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able... |
| CVE-2026-18369 | MEDIUM | 5.8 | — | Jul 30, 2026 | A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns... |
| CVE-2026-18362 | MEDIUM | 5.9 | 0.4% | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-fo... |
| CVE-2026-16971 | MEDIUM | 5.9 | 0.3% | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force a... |
| CVE-2026-16970 | MEDIUM | 4.2 | 0.2% | Jul 30, 2026 | The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Sto... |
| CVE-2026-44105 | MEDIUM | 6.6 | 0.1% | Jul 30, 2026 | The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local a... |
| CVE-2026-44103 | MEDIUM | 6.9 | 0.2% | Jul 30, 2026 | An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore ... |
| CVE-2026-44102 | MEDIUM | 6.9 | 0.2% | Jul 30, 2026 | An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f... |
| CVE-2026-64635 | MEDIUM | 5.3 | — | Jul 30, 2026 | Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an... |
| CVE-2026-59328 | MEDIUM | 4.2 | — | Jul 30, 2026 | Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browse... |
| CVE-2026-59327 | MEDIUM | 4.4 | — | Jul 30, 2026 | Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string... |
| CVE-2026-58040 | MEDIUM | 6.3 | — | Jul 30, 2026 | An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across ident... |
| CVE-2026-56850 | MEDIUM | 4.1 | 0.1% | Jul 30, 2026 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) cli... |
| CVE-2026-16531 | MEDIUM | 5.3 | 0.4% | Jul 30, 2026 | An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a ... |
| CVE-2026-16530 | MEDIUM | 6.5 | — | Jul 30, 2026 | A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in t... |
| CVE-2026-15382 | MEDIUM | 6.5 | 0.2% | Jul 30, 2026 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce chec... |
| CVE-2026-15257 | MEDIUM | 5.3 | 0.1% | Jul 30, 2026 | The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a fr... |
| CVE-2026-15255 | MEDIUM | 5.3 | 0.1% | Jul 30, 2026 | The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in ... |
| CVE-2026-15252 | MEDIUM | 5.4 | 0.1% | Jul 30, 2026 | The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX han... |
| CVE-2026-15250 | MEDIUM | 5.3 | 0.2% | Jul 30, 2026 | The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now