2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77534 | CRITICAL | 9.9 | 0.2% | Aug 26, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f... |
| CVE-2026-59683 | CRITICAL | 9.8 | 0.6% | Aug 26, 2026 | The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of ... |
| CVE-2026-59682 | CRITICAL | 9.1 | 0.5% | Aug 26, 2026 | Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3. |
| CVE-2026-80235 | CRITICAL | 9.8 | 0.7% | Aug 26, 2026 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote atta... |
| CVE-2026-77533 | CRITICAL | 9.9 | 1.0% | Aug 26, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability... |
| CVE-2026-18664 | CRITICAL | 9.1 | 0.3% | Aug 26, 2026 | When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address... |
| CVE-2026-18431 | CRITICAL | 9.8 | 0.6% | Aug 26, 2026 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the ... |
| CVE-2026-15203 | CRITICAL | 9.3 | 0.4% | Aug 26, 2026 | Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3... |
| CVE-2026-19632 | CRITICAL | 9.8 | 0.8% | Aug 26, 2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive In... |
| CVE-2026-80138 | CRITICAL | 9.8 | 1.2% | Aug 25, 2026 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to s... |
| CVE-2026-79911 | CRITICAL | 10 | 0.6% | Aug 25, 2026 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the functio... |
| CVE-2026-16645 | CRITICAL | 9.1 | 0.2% | Aug 25, 2026 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Bro... |
| CVE-2026-16644 | CRITICAL | 9.1 | 0.3% | Aug 25, 2026 | Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST v... |
| CVE-2026-16641 | CRITICAL | 9.8 | 0.3% | Aug 25, 2026 | Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. |
| CVE-2026-16639 | CRITICAL | 9.8 | 0.3% | Aug 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On all... |
| CVE-2026-78655 | CRITICAL | 9.1 | 0.2% | Aug 25, 2026 | Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earli... |
| CVE-2026-78619 | CRITICAL | 9.8 | 0.4% | Aug 25, 2026 | Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge beca... |
| CVE-2026-68525 | CRITICAL | 9.1 | 0.5% | Aug 25, 2026 | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security ... |
| CVE-2026-65905 | CRITICAL | 9.8 | 0.7% | Aug 25, 2026 | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize req... |
| CVE-2026-65637 | CRITICAL | 9.8 | 0.5% | Aug 25, 2026 | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects... |
| CVE-2026-65182 | CRITICAL | 9.1 | 0.5% | Aug 25, 2026 | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a... |
| CVE-2026-62862 | CRITICAL | 9.1 | 0.5% | Aug 25, 2026 | Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless ... |
| CVE-2026-80104 | CRITICAL | 9.8 | 0.7% | Aug 25, 2026 | DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the uplo... |
| CVE-2026-79290 | CRITICAL | 9.6 | 0.3% | Aug 25, 2026 | Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outsi... |
| CVE-2026-79282 | CRITICAL | 9.6 | 0.4% | Aug 25, 2026 | Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now