2026 CVE Vulnerabilities
43,308 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59534 | HIGH | 7.5 | — | Jul 27, 2026 | Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions. |
| CVE-2026-59532 | HIGH | 7.5 | — | Jul 27, 2026 | Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. |
| CVE-2026-59531 | HIGH | 7.5 | — | Jul 27, 2026 | Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. |
| CVE-2026-59530 | HIGH | 7.5 | — | Jul 27, 2026 | Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. |
| CVE-2026-59529 | HIGH | 7.5 | — | Jul 27, 2026 | Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. |
| CVE-2026-59528 | HIGH | 7.5 | — | Jul 27, 2026 | Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. |
| CVE-2026-65878 | HIGH | 8.3 | — | Jul 27, 2026 | Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path valida... |
| CVE-2026-65877 | HIGH | 8.2 | — | Jul 27, 2026 | Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of var... |
| CVE-2026-59690 | HIGH | 8 | 0.2% | Jul 27, 2026 | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M... |
| CVE-2026-59689 | HIGH | 8 | 0.2% | Jul 27, 2026 | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connectio... |
| CVE-2026-59688 | HIGH | 8.4 | 0.7% | Jul 27, 2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M... |
| CVE-2026-59687 | HIGH | 8.4 | 0.7% | Jul 27, 2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M... |
| CVE-2026-59686 | HIGH | 8.4 | 0.7% | Jul 27, 2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M... |
| CVE-2026-12991 | HIGH | 8.7 | — | Jul 27, 2026 | The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Visio... |
| CVE-2026-12990 | HIGH | 7.7 | — | Jul 27, 2026 | An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simul... |
| CVE-2026-12989 | HIGH | 8.7 | — | Jul 27, 2026 | A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated at... |
| CVE-2026-58389 | HIGH | 7.5 | — | Jul 27, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects A... |
| CVE-2026-55969 | HIGH | 7.5 | — | Jul 27, 2026 | Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This i... |
| CVE-2026-55968 | HIGH | 7.5 | — | Jul 27, 2026 | Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift ... |
| CVE-2026-49158 | HIGH | 7.5 | — | Jul 27, 2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This iss... |
| CVE-2026-48586 | HIGH | 7.5 | — | Jul 27, 2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D... |
| CVE-2026-48145 | HIGH | 7.5 | — | Jul 27, 2026 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects A... |
| CVE-2026-45112 | HIGH | 7.5 | — | Jul 27, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects A... |
| CVE-2026-43871 | HIGH | 7.5 | — | Jul 27, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.... |
| CVE-2026-41608 | HIGH | 7.5 | 1.1% | Jul 27, 2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now