2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71945 | CRITICAL | 9.8 | 2.1% | Aug 8, 2026 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj... |
| CVE-2026-71944 | CRITICAL | 9.8 | 2.1% | Aug 8, 2026 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj... |
| CVE-2026-14526 | CRITICAL | 9.8 | 0.6% | Aug 8, 2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and... |
| CVE-2026-46409 | CRITICAL | 9.6 | 0.4% | Aug 7, 2026 | OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to v... |
| CVE-2026-48170 | CRITICAL | 9.1 | 0.3% | Aug 7, 2026 | `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM ... |
| CVE-2026-47243 | CRITICAL | 9.2 | 0.2% | Aug 7, 2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2026-50540 | CRITICAL | 9.6 | — | Aug 7, 2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2026-61808 | CRITICAL | 9.8 | 0.3% | Aug 7, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds t... |
| CVE-2026-48039 | CRITICAL | 9.1 | — | Aug 7, 2026 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `A... |
| CVE-2026-71851 | CRITICAL | 9 | — | Aug 7, 2026 | crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in Crypt... |
| CVE-2026-64637 | CRITICAL | 9.9 | — | Aug 7, 2026 | Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an ... |
| CVE-2026-19264 | CRITICAL | 9.8 | — | Aug 7, 2026 | Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied pat... |
| CVE-2026-66914 | CRITICAL | 9.2 | — | Aug 7, 2026 | Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated... |
| CVE-2026-56793 | CRITICAL | 9.8 | — | Aug 7, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An ... |
| CVE-2026-71560 | CRITICAL | 9.1 | 0.2% | Aug 7, 2026 | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0... |
| CVE-2026-71558 | CRITICAL | 9.8 | 0.2% | Aug 7, 2026 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from ... |
| CVE-2026-54213 | CRITICAL | 9.2 | 0.7% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down whe... |
| CVE-2026-54212 | CRITICAL | 9.5 | 0.7% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow... |
| CVE-2026-54211 | CRITICAL | 9.5 | 0.6% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer o... |
| CVE-2026-54210 | CRITICAL | 9.5 | 0.7% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable... |
| CVE-2026-54203 | CRITICAL | 9.2 | 0.3% | Aug 7, 2026 | Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensiti... |
| CVE-2026-16258 | CRITICAL | 9.8 | 0.2% | Aug 7, 2026 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u... |
| CVE-2026-16038 | CRITICAL | 9.1 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an or... |
| CVE-2026-14205 | CRITICAL | 9.8 | 0.1% | Aug 7, 2026 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid... |
| CVE-2026-14365 | CRITICAL | 9.8 | 0.3% | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now