2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67215 | HIGH | 8.7 | 0.3% | Jul 29, 2026 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON... |
| CVE-2026-67214 | HIGH | 8.2 | 0.3% | Jul 29, 2026 | nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure mo... |
| CVE-2026-67213 | HIGH | 8.2 | 0.3% | Jul 29, 2026 | nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these fun... |
| CVE-2026-65889 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allow... |
| CVE-2026-55995 | HIGH | 8.7 | 0.3% | Jul 29, 2026 | A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects... |
| CVE-2026-65944 | HIGH | 8.8 | 0.1% | Jul 29, 2026 | Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 |
| CVE-2026-65943 | HIGH | 7.5 | 0.2% | Jul 29, 2026 | Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0 |
| CVE-2026-65885 | HIGH | 8.8 | 0.3% | Jul 29, 2026 | Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows au... |
| CVE-2026-50641 | HIGH | 7.1 | 0.2% | Jul 29, 2026 | Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in... |
| CVE-2026-44944 | HIGH | 8.5 | 0.1% | Jul 29, 2026 | An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control soc... |
| CVE-2026-14354 | HIGH | 8.7 | 0.1% | Jul 29, 2026 | CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorize... |
| CVE-2026-12927 | HIGH | 8.4 | 0.2% | Jul 29, 2026 | CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execut... |
| CVE-2026-14270 | HIGH | 8.8 | — | Jul 29, 2026 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerabl... |
| CVE-2026-18220 | HIGH | 7.8 | — | Jul 29, 2026 | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. T... |
| CVE-2026-16655 | HIGH | 7.2 | — | Jul 29, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2026-16597 | HIGH | 7.2 | — | Jul 29, 2026 | The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2026-12895 | HIGH | 7.1 | — | Jul 29, 2026 | SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries... |
| CVE-2026-58189 | HIGH | 8.2 | 0.4% | Jul 29, 2026 | Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. T... |
| CVE-2026-58188 | HIGH | 8.4 | 0.4% | Jul 29, 2026 | Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apach... |
| CVE-2026-58187 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of serv... |
| CVE-2026-58186 | HIGH | 8.2 | 0.4% | Jul 29, 2026 | The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This iss... |
| CVE-2026-58184 | HIGH | 7.5 | 0.3% | Jul 29, 2026 | The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition ... |
| CVE-2026-58183 | HIGH | 7.5 | 0.4% | Jul 29, 2026 | The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apach... |
| CVE-2026-58182 | HIGH | 8.6 | 0.3% | Jul 29, 2026 | The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issu... |
| CVE-2026-58181 | HIGH | 8.2 | 0.4% | Jul 29, 2026 | The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now