2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16839 | CRITICAL | 9.4 | 0.4% | Aug 19, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to an in... |
| CVE-2026-16834 | CRITICAL | 9.8 | 0.5% | Aug 19, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an integ... |
| CVE-2026-16822 | CRITICAL | 9.3 | 0.2% | Aug 19, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and mod... |
| CVE-2026-70496 | CRITICAL | 9.9 | 0.3% | Aug 19, 2026 | A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator... |
| CVE-2026-18315 | CRITICAL | 9.8 | 0.4% | Aug 19, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Thr... |
| CVE-2026-16835 | CRITICAL | 9.6 | 0.2% | Aug 19, 2026 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9... |
| CVE-2026-16687 | CRITICAL | 9.6 | 0.2% | Aug 19, 2026 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW9... |
| CVE-2026-72717 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.... |
| CVE-2026-72716 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.... |
| CVE-2026-71871 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.... |
| CVE-2026-71869 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.... |
| CVE-2026-71868 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.... |
| CVE-2026-71867 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.... |
| CVE-2026-71866 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8... |
| CVE-2026-71865 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.... |
| CVE-2026-71864 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.... |
| CVE-2026-66794 | CRITICAL | 9.3 | 0.4% | Aug 19, 2026 | A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows... |
| CVE-2026-63633 | CRITICAL | 9.8 | 0.6% | Aug 19, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/... |
| CVE-2026-62682 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.... |
| CVE-2026-62681 | CRITICAL | 9.3 | 0.5% | Aug 19, 2026 | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.... |
| CVE-2026-55194 | CRITICAL | 9.8 | 0.6% | Aug 19, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp... |
| CVE-2026-55191 | CRITICAL | 9.8 | 0.6% | Aug 19, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX ... |
| CVE-2026-32475 | CRITICAL | 9 | — | Aug 19, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. ... |
| CVE-2026-75143 | CRITICAL | 9.8 | 0.4% | Aug 19, 2026 | FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). libris... |
| CVE-2026-72530 | CRITICAL | 9 | 0.3% | Aug 19, 2026 | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now