2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56705 | CRITICAL | 9.8 | 0.5% | Aug 25, 2026 | Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated a... |
| CVE-2026-78267 | CRITICAL | 9.8 | 0.3% | Aug 24, 2026 | Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. |
| CVE-2026-78265 | CRITICAL | 9.8 | 0.3% | Aug 24, 2026 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. |
| CVE-2026-78262 | CRITICAL | 9.8 | 0.3% | Aug 24, 2026 | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. |
| CVE-2026-77337 | CRITICAL | 9.1 | 0.4% | Aug 24, 2026 | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versio... |
| CVE-2026-32563 | CRITICAL | 9.8 | 0.4% | Aug 24, 2026 | Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions. |
| CVE-2026-32559 | CRITICAL | 9.9 | 0.4% | Aug 24, 2026 | Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. |
| CVE-2026-32555 | CRITICAL | 9.3 | 0.2% | Aug 24, 2026 | Unauthenticated SQL Injection in Boost <= 2.0.4 versions. |
| CVE-2026-32554 | CRITICAL | 9.3 | 0.2% | Aug 24, 2026 | Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. |
| CVE-2026-77635 | CRITICAL | 9.2 | 0.3% | Aug 24, 2026 | CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective releas... |
| CVE-2026-52490 | CRITICAL | 9.8 | 0.4% | Aug 24, 2026 | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the proces... |
| CVE-2026-78555 | CRITICAL | 9.4 | 0.4% | Aug 24, 2026 | RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Althoug... |
| CVE-2026-39975 | CRITICAL | 9.4 | 0.3% | Aug 24, 2026 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly... |
| CVE-2026-76835 | CRITICAL | 9.1 | 0.6% | Aug 24, 2026 | OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, b... |
| CVE-2026-71933 | CRITICAL | 9.1 | 0.4% | Aug 24, 2026 | Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vul... |
| CVE-2026-71921 | CRITICAL | 9.8 | 3.2% | Aug 24, 2026 | Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi inter... |
| CVE-2026-71914 | CRITICAL | 9.8 | 3.1% | Aug 24, 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability i... |
| CVE-2026-78329 | CRITICAL | 9.8 | 0.3% | Aug 24, 2026 | Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.1... |
| CVE-2026-77915 | CRITICAL | 9.8 | 0.8% | Aug 24, 2026 | rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers t... |
| CVE-2026-71300 | CRITICAL | 9.8 | 0.4% | Aug 24, 2026 | Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam... |
| CVE-2026-66906 | CRITICAL | 9.1 | 0.4% | Aug 24, 2026 | Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: ... |
| CVE-2026-76071 | CRITICAL | 9.8 | 1.4% | Aug 24, 2026 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated... |
| CVE-2026-76070 | CRITICAL | 9.8 | 1.3% | Aug 24, 2026 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated... |
| CVE-2026-78387 | CRITICAL | 9.4 | 0.4% | Aug 24, 2026 | RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config en... |
| CVE-2026-19874 | CRITICAL | 9.1 | 0.7% | Aug 24, 2026 | A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now