2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76158 | CRITICAL | 9.3 | 0.4% | Aug 21, 2026 | External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v... |
| CVE-2026-76156 | CRITICAL | 9.4 | 0.8% | Aug 21, 2026 | OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenti... |
| CVE-2026-76155 | CRITICAL | 9.3 | 0.3% | Aug 21, 2026 | Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain... |
| CVE-2026-77651 | CRITICAL | 9.8 | 0.5% | Aug 21, 2026 | The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate,... |
| CVE-2026-77650 | CRITICAL | 9.8 | 0.4% | Aug 21, 2026 | The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the ... |
| CVE-2026-77649 | CRITICAL | 9.8 | 0.4% | Aug 21, 2026 | The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate... |
| CVE-2026-77647 | CRITICAL | 9.8 | 2.6% | Aug 20, 2026 | SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August... |
| CVE-2026-77645 | CRITICAL | 9.2 | 0.5% | Aug 20, 2026 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili... |
| CVE-2026-77644 | CRITICAL | 9.3 | 0.3% | Aug 20, 2026 | A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise ... |
| CVE-2026-77642 | CRITICAL | 9.3 | 0.2% | Aug 20, 2026 | tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected s... |
| CVE-2026-72843 | CRITICAL | 9.8 | 0.8% | Aug 20, 2026 | The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/... |
| CVE-2026-69851 | CRITICAL | 9.9 | 0.4% | Aug 20, 2026 | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a ... |
| CVE-2026-69836 | CRITICAL | 10 | 1.6% | Aug 20, 2026 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69555 | CRITICAL | 10 | 0.5% | Aug 20, 2026 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69400 | CRITICAL | 9.6 | 0.6% | Aug 20, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize... |
| CVE-2026-68789 | CRITICAL | 9.9 | 0.5% | Aug 20, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut... |
| CVE-2026-68782 | CRITICAL | 9.9 | 0.5% | Aug 20, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut... |
| CVE-2026-66309 | CRITICAL | 9.1 | 0.5% | Aug 20, 2026 | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-65816 | CRITICAL | 10 | 0.5% | Aug 20, 2026 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a ... |
| CVE-2026-65801 | CRITICAL | 10 | 0.5% | Aug 20, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ov... |
| CVE-2026-65770 | CRITICAL | 10 | 0.6% | Aug 20, 2026 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache ... |
| CVE-2026-62834 | CRITICAL | 9.8 | 0.3% | Aug 20, 2026 | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privil... |
| CVE-2026-55769 | CRITICAL | 9.4 | 0.5% | Aug 20, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and ... |
| CVE-2026-19437 | CRITICAL | 9.8 | 0.5% | Aug 20, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov... |
| CVE-2026-18835 | CRITICAL | 9.9 | 0.6% | Aug 20, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now