2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78372 | CRITICAL | 9.2 | 0.5% | Aug 24, 2026 | RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked ... |
| CVE-2026-78370 | CRITICAL | 9.2 | 0.5% | Aug 24, 2026 | RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated rem... |
| CVE-2026-77995 | CRITICAL | 10 | 0.3% | Aug 24, 2026 | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On ... |
| CVE-2026-76840 | CRITICAL | 9.6 | 0.3% | Aug 24, 2026 | RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper ... |
| CVE-2026-67602 | CRITICAL | 9.1 | 0.6% | Aug 24, 2026 | phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attacke... |
| CVE-2026-59568 | CRITICAL | 9.1 | 0.4% | Aug 24, 2026 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthe... |
| CVE-2026-59564 | CRITICAL | 9.1 | 0.3% | Aug 24, 2026 | An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and th... |
| CVE-2026-78365 | CRITICAL | 9.3 | 0.4% | Aug 24, 2026 | Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 all... |
| CVE-2026-66650 | CRITICAL | 9.8 | — | Aug 24, 2026 | Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions. |
| CVE-2026-66648 | CRITICAL | 9.8 | — | Aug 24, 2026 | Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. |
| CVE-2026-66587 | CRITICAL | 9.8 | — | Aug 24, 2026 | Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. |
| CVE-2026-32558 | CRITICAL | 9.8 | — | Aug 24, 2026 | Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. |
| CVE-2026-32551 | CRITICAL | 9.3 | 0.2% | Aug 24, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DiviNext Woo Essen... |
| CVE-2026-28165 | CRITICAL | 9.8 | — | Aug 24, 2026 | Unauthenticated Privilege Escalation in Digits <= 9.2 versions. |
| CVE-2026-66897 | CRITICAL | 9.9 | 0.6% | Aug 24, 2026 | A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions,... |
| CVE-2026-77994 | CRITICAL | 9.3 | 0.2% | Aug 24, 2026 | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Build... |
| CVE-2026-78211 | CRITICAL | 9.8 | 1.5% | Aug 24, 2026 | 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remo... |
| CVE-2026-78169 | CRITICAL | 9.9 | 0.4% | Aug 24, 2026 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file... |
| CVE-2026-78168 | CRITICAL | 9.8 | 0.9% | Aug 24, 2026 | A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_... |
| CVE-2026-78167 | CRITICAL | 10 | 1.0% | Aug 24, 2026 | A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session... |
| CVE-2026-78207 | CRITICAL | 9.4 | 0.4% | Aug 24, 2026 | exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto_... |
| CVE-2026-78183 | CRITICAL | 9.8 | 0.5% | Aug 23, 2026 | DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of th... |
| CVE-2026-8445 | CRITICAL | 9.8 | 0.4% | Aug 23, 2026 | justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in... |
| CVE-2026-7808 | CRITICAL | 9.8 | 0.4% | Aug 23, 2026 | justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., ... |
| CVE-2026-5388 | CRITICAL | 9.8 | 0.3% | Aug 23, 2026 | justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_st... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now