2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77992 | CRITICAL | 9.5 | 0.3% | Aug 22, 2026 | Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateCommen... |
| CVE-2026-76607 | CRITICAL | 10 | 0.2% | Aug 22, 2026 | Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2. |
| CVE-2026-76606 | CRITICAL | 10 | 0.3% | Aug 22, 2026 | Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2. |
| CVE-2026-76605 | CRITICAL | 10 | 0.4% | Aug 22, 2026 | Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2. |
| CVE-2026-76604 | CRITICAL | 10 | 0.4% | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP... |
| CVE-2026-76602 | CRITICAL | 9.3 | 0.2% | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in l... |
| CVE-2026-76571 | CRITICAL | 9.3 | 0.3% | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - T... |
| CVE-2026-75870 | CRITICAL | 9.1 | 0.5% | Aug 22, 2026 | Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared... |
| CVE-2026-75866 | CRITICAL | 9.1 | 0.5% | Aug 22, 2026 | Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant t... |
| CVE-2026-77946 | CRITICAL | 10 | 0.6% | Aug 22, 2026 | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe... |
| CVE-2026-78003 | CRITICAL | 9.8 | 0.6% | Aug 22, 2026 | The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in... |
| CVE-2026-12710 | CRITICAL | 9.3 | 0.3% | Aug 22, 2026 | A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025... |
| CVE-2026-77002 | CRITICAL | 9.8 | 0.3% | Aug 22, 2026 | The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity ... |
| CVE-2026-77001 | CRITICAL | 9.8 | 0.4% | Aug 22, 2026 | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authen... |
| CVE-2026-77000 | CRITICAL | 9.8 | 0.3% | Aug 22, 2026 | The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with... |
| CVE-2026-49849 | CRITICAL | 9.1 | 0.7% | Aug 21, 2026 | xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allo... |
| CVE-2026-77415 | CRITICAL | 9.3 | 0.5% | Aug 21, 2026 | JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain s... |
| CVE-2026-77414 | CRITICAL | 9.3 | 0.3% | Aug 21, 2026 | JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup fun... |
| CVE-2026-77413 | CRITICAL | 9.3 | 0.4% | Aug 21, 2026 | JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lack... |
| CVE-2026-76904 | CRITICAL | 9.8 | 1.8% | Aug 21, 2026 | GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to v... |
| CVE-2026-62283 | CRITICAL | 9.9 | 0.4% | Aug 21, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 t... |
| CVE-2026-61539 | CRITICAL | 10 | 0.7% | Aug 21, 2026 | Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference ... |
| CVE-2026-59989 | CRITICAL | 9.2 | 0.3% | Aug 21, 2026 | Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine... |
| CVE-2026-77810 | CRITICAL | 9.9 | 0.3% | Aug 21, 2026 | In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties i... |
| CVE-2026-62674 | CRITICAL | 9 | 0.3% | Aug 21, 2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /ses... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now