2026 CVE Vulnerabilities
43,090 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14859 | — | — | — | Aug 12, 2026 | The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a... |
| CVE-2026-14858 | — | — | — | Aug 12, 2026 | The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi... |
| CVE-2026-14857 | — | — | — | Aug 12, 2026 | The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his... |
| CVE-2026-13613 | — | — | — | Aug 12, 2026 | The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using ... |
| CVE-2026-13612 | — | — | — | Aug 12, 2026 | The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al... |
| CVE-2026-13177 | — | — | — | Aug 12, 2026 | The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user... |
| CVE-2026-13171 | — | — | — | Aug 12, 2026 | The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration han... |
| CVE-2026-13168 | — | — | — | Aug 12, 2026 | The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users... |
| CVE-2026-12976 | — | — | — | Aug 12, 2026 | The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a... |
| CVE-2026-64954 | HIGH | 8.2 | — | Aug 12, 2026 | Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, th... |
| CVE-2026-12235 | MEDIUM | 6.3 | — | Aug 12, 2026 | The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (p... |
| CVE-2026-12234 | HIGH | 7.8 | — | Aug 12, 2026 | The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c sn... |
| CVE-2026-12233 | MEDIUM | 5.9 | — | Aug 12, 2026 | The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre... |
| CVE-2026-12232 | MEDIUM | 6.1 | — | Aug 12, 2026 | The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a cal... |
| CVE-2026-9318 | MEDIUM | 5.4 | 0.2% | Aug 12, 2026 | tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows... |
| CVE-2026-19588 | MEDIUM | 6.5 | — | Aug 12, 2026 | Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. |
| CVE-2026-19587 | MEDIUM | 6.5 | — | Aug 12, 2026 | Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation. |
| CVE-2026-18961 | HIGH | 8.1 | 0.5% | Aug 12, 2026 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnera... |
| CVE-2026-73122 | HIGH | 7.7 | 0.2% | Aug 12, 2026 | A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vuln... |
| CVE-2026-72526 | CRITICAL | 9.9 | — | Aug 12, 2026 | A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-man... |
| CVE-2026-70398 | CRITICAL | 9.6 | — | Aug 12, 2026 | A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerabil... |
| CVE-2026-66878 | HIGH | 7.7 | — | Aug 12, 2026 | A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable... |
| CVE-2026-64927 | MEDIUM | 6.4 | 0.1% | Aug 12, 2026 | A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissio... |
| CVE-2026-6484 | HIGH | 8.2 | — | Aug 12, 2026 | In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution. |
| CVE-2026-68450 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on duplicate reloc root in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now