2026 CVE Vulnerabilities
43,053 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14205 | CRITICAL | 9.8 | 0.1% | Aug 7, 2026 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid... |
| CVE-2026-14365 | CRITICAL | 9.8 | 0.3% | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ... |
| CVE-2026-14364 | CRITICAL | 9.8 | 0.3% | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via imp... |
| CVE-2026-70332 | CRITICAL | 9.6 | 0.4% | Aug 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-68823 | CRITICAL | 9.1 | 0.5% | Aug 7, 2026 | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n... |
| CVE-2026-65667 | CRITICAL | 10 | 0.4% | Aug 7, 2026 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-63508 | CRITICAL | 10 | 0.5% | Aug 7, 2026 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev... |
| CVE-2026-62896 | CRITICAL | 9.6 | 0.4% | Aug 7, 2026 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-62873 | CRITICAL | 9.8 | 0.4% | Aug 7, 2026 | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevat... |
| CVE-2026-62836 | CRITICAL | 10 | 0.4% | Aug 7, 2026 | Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized... |
| CVE-2026-62830 | CRITICAL | 9.9 | 0.4% | Aug 7, 2026 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-59118 | CRITICAL | 9.3 | 0.4% | Aug 7, 2026 | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-59115 | CRITICAL | 9.9 | 0.6% | Aug 7, 2026 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges ove... |
| CVE-2026-56162 | CRITICAL | 10 | 0.5% | Aug 7, 2026 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-56161 | CRITICAL | 9.6 | 0.4% | Aug 7, 2026 | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. |
| CVE-2026-50515 | CRITICAL | 9.9 | 0.9% | Aug 7, 2026 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. |
| CVE-2026-50481 | CRITICAL | 9.9 | 0.5% | Aug 7, 2026 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privile... |
| CVE-2026-70558 | CRITICAL | 9.8 | 0.6% | Aug 6, 2026 | Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) ... |
| CVE-2026-67689 | CRITICAL | 9.8 | 0.4% | Aug 6, 2026 | SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or... |
| CVE-2026-67688 | CRITICAL | 9.8 | 0.3% | Aug 6, 2026 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module.... |
| CVE-2026-67622 | CRITICAL | 9.9 | 0.2% | Aug 6, 2026 | Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration th... |
| CVE-2026-5857 | CRITICAL | 9.2 | 0.5% | Aug 6, 2026 | Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking ... |
| CVE-2026-53984 | CRITICAL | 9.1 | 0.4% | Aug 6, 2026 | Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerabilit... |
| CVE-2026-53983 | CRITICAL | 9.2 | 0.3% | Aug 6, 2026 | Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital... |
| CVE-2026-48088 | CRITICAL | 9.4 | 0.3% | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now