2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17347 | HIGH | 8.8 | 0.3% | Jul 31, 2026 | The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that ... |
| CVE-2026-17346 | HIGH | 8.8 | 0.4% | Jul 31, 2026 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatin... |
| CVE-2026-10686 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing ... |
| CVE-2026-18446 | HIGH | 7.5 | — | Jul 31, 2026 | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a refer... |
| CVE-2026-10685 | HIGH | 7.6 | 0.2% | Jul 31, 2026 | The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked... |
| CVE-2026-18358 | HIGH | 7.5 | 0.4% | Jul 31, 2026 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mo... |
| CVE-2026-46593 | HIGH | 8.6 | — | Jul 31, 2026 | A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input... |
| CVE-2026-62391 | HIGH | 8.1 | 0.4% | Jul 31, 2026 | The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend... |
| CVE-2026-16843 | HIGH | 7.2 | 0.9% | Jul 31, 2026 | Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio... |
| CVE-2026-15722 | HIGH | 7.5 | 0.5% | Jul 31, 2026 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function ... |
| CVE-2026-11770 | HIGH | 7.5 | 0.5% | Jul 31, 2026 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the Cle... |
| CVE-2026-10079 | HIGH | 8.5 | 0.2% | Jul 31, 2026 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, AC... |
| CVE-2026-65313 | HIGH | 8.1 | 0.2% | Jul 31, 2026 | A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-c... |
| CVE-2026-65310 | HIGH | 7.5 | 0.3% | Jul 31, 2026 | ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configu... |
| CVE-2026-65309 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible form... |
| CVE-2026-18215 | HIGH | 8.1 | 0.2% | Jul 31, 2026 | Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization... |
| CVE-2026-18214 | HIGH | 8.1 | 0.2% | Jul 31, 2026 | Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor... |
| CVE-2026-16236 | HIGH | 8.8 | 0.6% | Jul 31, 2026 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5... |
| CVE-2026-15258 | HIGH | 8.1 | 0.2% | Jul 31, 2026 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-fe... |
| CVE-2026-15048 | HIGH | 7.5 | 0.1% | Jul 31, 2026 | The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowin... |
| CVE-2026-14930 | HIGH | 7.5 | 0.1% | Jul 31, 2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front... |
| CVE-2026-14830 | HIGH | 7.5 | — | Jul 31, 2026 | The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually... |
| CVE-2026-14333 | HIGH | 7.5 | — | Jul 31, 2026 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a p... |
| CVE-2026-14319 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurri... |
| CVE-2026-13609 | HIGH | 8.8 | 0.2% | Jul 31, 2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value af... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now