2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31309 | CRITICAL | 9.8 | 0.3% | Jul 8, 2026 | Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows a... |
| CVE-2026-54527 | CRITICAL | 9 | 0.3% | Jul 8, 2026 | JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() metho... |
| CVE-2026-8801 | CRITICAL | 9.8 | 0.3% | Jul 8, 2026 | Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: ... |
| CVE-2026-8649 | CRITICAL | 9.8 | 0.2% | Jul 8, 2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Report... |
| CVE-2026-29009 | CRITICAL | 9.8 | 0.5% | Jul 8, 2026 | U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFI... |
| CVE-2026-9074 | CRITICAL | 9.8 | 0.4% | Jul 8, 2026 | IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulner... |
| CVE-2026-59702 | CRITICAL | 9.3 | 0.3% | Jul 8, 2026 | repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated ... |
| CVE-2026-3144 | CRITICAL | 9.8 | 0.4% | Jul 8, 2026 | IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized ac... |
| CVE-2026-15062 | CRITICAL | 9.6 | 0.3% | Jul 8, 2026 | SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allo... |
| CVE-2026-58480 | CRITICAL | 9.8 | — | Jul 8, 2026 | Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability... |
| CVE-2026-54061 | CRITICAL | 9.1 | — | Jul 8, 2026 | Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for e... |
| CVE-2026-8307 | CRITICAL | 9.8 | — | Jul 8, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Desig... |
| CVE-2026-14454 | CRITICAL | 9.8 | 0.4% | Jul 8, 2026 | Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD ... |
| CVE-2026-41042 | CRITICAL | 9.1 | — | Jul 8, 2026 | Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java... |
| CVE-2026-9695 | CRITICAL | 9.8 | 0.3% | Jul 8, 2026 | An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an a... |
| CVE-2026-12153 | CRITICAL | 9.8 | 0.4% | Jul 8, 2026 | The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.... |
| CVE-2026-9701 | CRITICAL | 9.8 | 0.3% | Jul 8, 2026 | The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and includ... |
| CVE-2026-14487 | CRITICAL | 9.1 | 0.7% | Jul 8, 2026 | The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val... |
| CVE-2026-60002 | CRITICAL | 9.4 | 0.3% | Jul 8, 2026 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This ... |
| CVE-2026-56843 | CRITICAL | 9.9 | 0.3% | Jul 8, 2026 | Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated custo... |
| CVE-2026-59705 | CRITICAL | 9.8 | 0.5% | Jul 7, 2026 | mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers t... |
| CVE-2026-37271 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GA... |
| CVE-2026-37270 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper passwor... |
| CVE-2026-14740 | CRITICAL | 9.1 | 0.4% | Jul 7, 2026 | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The pr... |
| CVE-2026-14739 | CRITICAL | 9.8 | 0.4% | Jul 7, 2026 | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeho... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now