2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-74014 | CRITICAL | 9.9 | — | Aug 20, 2026 | Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. |
| CVE-2026-74001 | CRITICAL | 9.8 | — | Aug 20, 2026 | Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. |
| CVE-2026-73993 | CRITICAL | 9.8 | — | Aug 20, 2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. |
| CVE-2026-73992 | CRITICAL | 9.9 | — | Aug 20, 2026 | Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. |
| CVE-2026-68566 | CRITICAL | 9.3 | — | Aug 20, 2026 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. |
| CVE-2026-66682 | CRITICAL | 9.8 | — | Aug 20, 2026 | Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. |
| CVE-2026-66680 | CRITICAL | 9.3 | — | Aug 20, 2026 | Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. |
| CVE-2026-66672 | CRITICAL | 9.8 | — | Aug 20, 2026 | Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. |
| CVE-2026-66649 | CRITICAL | 9.3 | — | Aug 20, 2026 | Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. |
| CVE-2026-66609 | CRITICAL | 9.3 | — | Aug 20, 2026 | Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. |
| CVE-2026-66600 | CRITICAL | 9.1 | — | Aug 20, 2026 | Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. |
| CVE-2026-66593 | CRITICAL | 9.3 | — | Aug 20, 2026 | Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. |
| CVE-2026-66592 | CRITICAL | 9.3 | — | Aug 20, 2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. |
| CVE-2026-66583 | CRITICAL | 9.8 | — | Aug 20, 2026 | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. |
| CVE-2026-14950 | CRITICAL | 9.8 | 0.6% | Aug 20, 2026 | An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session aft... |
| CVE-2026-75860 | CRITICAL | 9.8 | 0.3% | Aug 20, 2026 | The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its a... |
| CVE-2026-76886 | CRITICAL | 9.8 | 0.3% | Aug 19, 2026 | C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service |
| CVE-2026-76850 | CRITICAL | 9.8 | 1.4% | Aug 19, 2026 | LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch... |
| CVE-2026-76590 | CRITICAL | 9.9 | 0.6% | Aug 19, 2026 | A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionalit... |
| CVE-2026-76589 | CRITICAL | 9.9 | 0.6% | Aug 19, 2026 | A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/my... |
| CVE-2026-76404 | CRITICAL | 9.1 | 0.6% | Aug 19, 2026 | In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands... |
| CVE-2026-76312 | CRITICAL | 9.4 | 0.4% | Aug 19, 2026 | In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hyperte... |
| CVE-2026-76311 | CRITICAL | 9.4 | 0.4% | Aug 19, 2026 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded repo... |
| CVE-2026-76310 | CRITICAL | 9.4 | 0.4% | Aug 19, 2026 | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded repo... |
| CVE-2026-76584 | CRITICAL | 9.9 | — | Aug 19, 2026 | A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionali... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now