2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-60090 | CRITICAL | 9.8 | 0.4% | Jul 11, 2026 | PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowled... |
| CVE-2026-56372 | CRITICAL | 9.1 | 0.1% | Jul 11, 2026 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers... |
| CVE-2026-57827 | CRITICAL | 9.8 | 0.3% | Jul 11, 2026 | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFi... |
| CVE-2026-20744 | CRITICAL | 9.8 | 0.5% | Jul 10, 2026 | The charging station websocket endpoint accepts connections without proper authentication, which could lead to privileg... |
| CVE-2026-15089 | CRITICAL | 9.1 | 0.2% | Jul 10, 2026 | vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.... |
| CVE-2026-14480 | CRITICAL | 9.9 | 0.6% | Jul 10, 2026 | OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload wor... |
| CVE-2026-11913 | CRITICAL | 9.8 | 0.2% | Jul 10, 2026 | vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. |
| CVE-2026-55884 | CRITICAL | 9.2 | 0.4% | Jul 10, 2026 | Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP... |
| CVE-2026-12535 | CRITICAL | 9.8 | 0.4% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field a... |
| CVE-2026-10768 | CRITICAL | 9.8 | 0.3% | Jul 10, 2026 | Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov W... |
| CVE-2026-9726 | CRITICAL | 9.8 | 0.3% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal Alternativ... |
| CVE-2026-57807 | CRITICAL | 9.8 | 0.4% | Jul 10, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Si... |
| CVE-2026-57216 | CRITICAL | 10 | 0.3% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Str... |
| CVE-2026-57211 | CRITICAL | 10 | 0.3% | Jul 10, 2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin stati... |
| CVE-2026-55879 | CRITICAL | 9.3 | 0.3% | Jul 10, 2026 | OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom ... |
| CVE-2026-12761 | CRITICAL | 9.8 | 0.5% | Jul 10, 2026 | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to auth... |
| CVE-2026-57158 | CRITICAL | 9.1 | 0.7% | Jul 10, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GF... |
| CVE-2026-57156 | CRITICAL | 9.8 | 0.7% | Jul 10, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients conta... |
| CVE-2026-61459 | CRITICAL | 9.8 | 0.4% | Jul 10, 2026 | MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubect... |
| CVE-2026-5801 | CRITICAL | 9.8 | — | Jul 10, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics... |
| CVE-2026-59151 | CRITICAL | 9.6 | 0.3% | Jul 10, 2026 | Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asser... |
| CVE-2026-2397 | CRITICAL | 9.8 | — | Jul 10, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automa... |
| CVE-2026-58492 | CRITICAL | 9.2 | — | Jul 10, 2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its t... |
| CVE-2026-51119 | CRITICAL | 9.1 | — | Jul 10, 2026 | An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser co... |
| CVE-2026-55500 | CRITICAL | 9.9 | — | Jul 10, 2026 | 9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now