2026 CVE Vulnerabilities
43,308 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66729 | HIGH | 8.7 | 0.5% | Jul 27, 2026 | facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows u... |
| CVE-2026-24252 | HIGH | 7.8 | — | Jul 27, 2026 | NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of... |
| CVE-2026-17192 | HIGH | 8.5 | 2.3% | Jul 27, 2026 | A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authentica... |
| CVE-2026-66399 | HIGH | 8.5 | 0.2% | Jul 27, 2026 | phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows admi... |
| CVE-2026-66397 | HIGH | 8.6 | 0.3% | Jul 27, 2026 | phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, al... |
| CVE-2026-59251 | HIGH | 7.5 | 0.3% | Jul 27, 2026 | Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthentica... |
| CVE-2026-59250 | HIGH | 8.3 | 0.7% | Jul 27, 2026 | Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corru... |
| CVE-2026-58227 | HIGH | 7.5 | 0.4% | Jul 27, 2026 | The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a ... |
| CVE-2026-55953 | HIGH | 7.4 | 0.2% | Jul 27, 2026 | The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in... |
| CVE-2026-55737 | HIGH | 7.5 | 0.1% | Jul 27, 2026 | Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can ... |
| CVE-2026-54890 | HIGH | 7.5 | 0.3% | Jul 27, 2026 | Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modu... |
| CVE-2026-42792 | HIGH | 7.5 | 0.4% | Jul 27, 2026 | Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote att... |
| CVE-2026-66427 | HIGH | 7.6 | — | Jul 27, 2026 | Administrator SQL Injection in WP Google Review Slider <= 18.4 versions. |
| CVE-2026-66050 | HIGH | 8.7 | 0.7% | Jul 27, 2026 | NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows una... |
| CVE-2026-59558 | HIGH | 7.1 | — | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. |
| CVE-2026-59556 | HIGH | 7.1 | — | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. |
| CVE-2026-59553 | HIGH | 7.1 | — | Jul 27, 2026 | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. |
| CVE-2026-59552 | HIGH | 7.2 | — | Jul 27, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. |
| CVE-2026-59551 | HIGH | 8.5 | — | Jul 27, 2026 | Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. |
| CVE-2026-59548 | HIGH | 7.5 | — | Jul 27, 2026 | Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. |
| CVE-2026-59546 | HIGH | 7.4 | — | Jul 27, 2026 | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. |
| CVE-2026-59539 | HIGH | 7.5 | — | Jul 27, 2026 | Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. |
| CVE-2026-59537 | HIGH | 7.6 | — | Jul 27, 2026 | Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versio... |
| CVE-2026-59536 | HIGH | 7.5 | — | Jul 27, 2026 | Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. |
| CVE-2026-59535 | HIGH | 7.3 | — | Jul 27, 2026 | Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now