2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57517 | CRITICAL | 9.8 | 0.6% | Jul 1, 2026 | Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote atta... |
| CVE-2026-24270 | CRITICAL | 9.8 | — | Jul 1, 2026 | NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of... |
| CVE-2026-23537 | CRITICAL | 9.1 | 0.6% | Jul 1, 2026 | A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticat... |
| CVE-2026-57692 | CRITICAL | 9.8 | — | Jul 1, 2026 | Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects Pr... |
| CVE-2026-53355 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB... |
| CVE-2026-13603 | CRITICAL | 9 | 0.3% | Jul 1, 2026 | The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially othe... |
| CVE-2026-14198 | CRITICAL | 9.1 | 0.3% | Jul 1, 2026 | @fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching m... |
| CVE-2026-11387 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera... |
| CVE-2026-10539 | CRITICAL | 9.5 | 0.2% | Jul 1, 2026 | A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain con... |
| CVE-2026-7840 | CRITICAL | 9.8 | 1.2% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The func... |
| CVE-2026-7839 | CRITICAL | 9.1 | 0.3% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repea... |
| CVE-2026-6070 | CRITICAL | 9.1 | 0.4% | Jul 1, 2026 | The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to... |
| CVE-2026-56700 | CRITICAL | 9.8 | 1.7% | Jun 30, 2026 | Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Sch... |
| CVE-2026-56415 | CRITICAL | 10 | 3.1% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable... |
| CVE-2026-56413 | CRITICAL | 10 | 3.1% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens ... |
| CVE-2026-56278 | CRITICAL | 9.3 | 0.4% | Jun 30, 2026 | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the exp... |
| CVE-2026-55721 | CRITICAL | 9.3 | 0.4% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debu... |
| CVE-2026-50110 | CRITICAL | 9.3 | 0.1% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configu... |
| CVE-2026-14152 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromi... |
| CVE-2026-14121 | CRITICAL | 9.8 | 0.3% | Jun 30, 2026 | Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbit... |
| CVE-2026-14120 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compr... |
| CVE-2026-14113 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromis... |
| CVE-2026-14109 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compro... |
| CVE-2026-14106 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a... |
| CVE-2026-14104 | CRITICAL | 9.8 | 0.3% | Jun 30, 2026 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote at... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now