2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54663 | MEDIUM | 6.1 | 0.2% | Jul 29, 2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol... |
| CVE-2026-67217 | MEDIUM | 6.9 | 0.2% | Jul 29, 2026 | cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a repl... |
| CVE-2026-66490 | MEDIUM | 6.1 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 |
| CVE-2026-66489 | MEDIUM | 5.3 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 |
| CVE-2026-66488 | MEDIUM | 5.3 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 |
| CVE-2026-66400 | MEDIUM | 6.3 | 0.2% | Jul 29, 2026 | Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php wh... |
| CVE-2026-18174 | MEDIUM | 5.3 | 0.2% | Jul 29, 2026 | @fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header ... |
| CVE-2026-16751 | MEDIUM | 6.5 | 0.2% | Jul 29, 2026 | Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an auth... |
| CVE-2026-65946 | MEDIUM | 6.1 | 0.1% | Jul 29, 2026 | Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0 |
| CVE-2026-65891 | MEDIUM | 6.5 | 0.2% | Jul 29, 2026 | Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function ... |
| CVE-2026-44943 | MEDIUM | 6.9 | 0.3% | Jul 29, 2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows rem... |
| CVE-2026-33385 | MEDIUM | 5.1 | 0.2% | Jul 29, 2026 | A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a hig... |
| CVE-2026-8791 | MEDIUM | 6.4 | — | Jul 29, 2026 | The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` ... |
| CVE-2026-7436 | MEDIUM | 6.4 | — | Jul 29, 2026 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text... |
| CVE-2026-6089 | MEDIUM | 4.9 | — | Jul 29, 2026 | The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor... |
| CVE-2026-5060 | MEDIUM | 6.5 | — | Jul 29, 2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure D... |
| CVE-2026-56390 | MEDIUM | 4.6 | 0.1% | Jul 29, 2026 | GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifyi... |
| CVE-2026-56389 | MEDIUM | 6.8 | 0.2% | Jul 29, 2026 | GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gram... |
| CVE-2026-50642 | MEDIUM | 4.8 | 0.3% | Jul 29, 2026 | diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application... |
| CVE-2026-4604 | MEDIUM | 5.3 | — | Jul 29, 2026 | The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2026-65100 | MEDIUM | 6.3 | 0.3% | Jul 29, 2026 | Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so... |
| CVE-2026-58160 | MEDIUM | 6.5 | 0.4% | Jul 29, 2026 | Apache Traffic Server reads out of bounds while parsing DNS answers. This issue affects Apache Traffic Server: from 8.0... |
| CVE-2026-18207 | MEDIUM | 6.5 | 0.3% | Jul 29, 2026 | A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group m... |
| CVE-2026-18201 | MEDIUM | 5.5 | 0.3% | Jul 29, 2026 | Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discov... |
| CVE-2026-9720 | MEDIUM | 4.3 | 0.1% | Jul 29, 2026 | The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now