2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76244 | CRITICAL | 9.1 | 0.2% | Aug 19, 2026 | stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse network... |
| CVE-2026-76243 | CRITICAL | 9.2 | 0.6% | Aug 19, 2026 | stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments... |
| CVE-2026-76242 | CRITICAL | 9.1 | 0.3% | Aug 19, 2026 | stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-... |
| CVE-2026-74804 | CRITICAL | 9.3 | 0.3% | Aug 19, 2026 | Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filte... |
| CVE-2026-74803 | CRITICAL | 10 | 0.3% | Aug 19, 2026 | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbi... |
| CVE-2026-51366 | CRITICAL | 9.9 | 0.5% | Aug 19, 2026 | SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary c... |
| CVE-2026-16019 | CRITICAL | 9.8 | 0.3% | Aug 19, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation ... |
| CVE-2026-73391 | CRITICAL | 9.3 | — | Aug 19, 2026 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. |
| CVE-2026-73390 | CRITICAL | 9.8 | 0.3% | Aug 19, 2026 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. |
| CVE-2026-73389 | CRITICAL | 9.8 | 0.3% | Aug 19, 2026 | Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. |
| CVE-2026-73388 | CRITICAL | 9.3 | — | Aug 19, 2026 | Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. |
| CVE-2026-73364 | CRITICAL | 9.8 | — | Aug 19, 2026 | Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. |
| CVE-2026-73347 | CRITICAL | 9.8 | 0.3% | Aug 19, 2026 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. |
| CVE-2026-73185 | CRITICAL | 9.3 | 0.2% | Aug 19, 2026 | Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. |
| CVE-2026-73183 | CRITICAL | 9.3 | — | Aug 19, 2026 | Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. |
| CVE-2026-67364 | CRITICAL | 10 | 0.3% | Aug 19, 2026 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.... |
| CVE-2026-66613 | CRITICAL | 9.8 | 0.5% | Aug 19, 2026 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. |
| CVE-2026-19490 | CRITICAL | 9.8 | 3.4% | Aug 19, 2026 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 thr... |
| CVE-2026-72889 | CRITICAL | 9.8 | 0.1% | Aug 19, 2026 | Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves ... |
| CVE-2026-58082 | CRITICAL | 9.8 | 0.4% | Aug 19, 2026 | The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ... |
| CVE-2026-58081 | CRITICAL | 9.8 | 0.4% | Aug 19, 2026 | Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied outp... |
| CVE-2026-18937 | CRITICAL | 9 | 0.4% | Aug 19, 2026 | The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input o... |
| CVE-2026-18776 | CRITICAL | 9.8 | 0.3% | Aug 19, 2026 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, all... |
| CVE-2026-18051 | CRITICAL | 10 | 0.4% | Aug 19, 2026 | The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache fil... |
| CVE-2026-18031 | CRITICAL | 9.8 | 0.3% | Aug 19, 2026 | The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now