2026 CVE Vulnerabilities
43,308 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17527 | HIGH | 7.7 | — | Jul 27, 2026 | In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only acc... |
| CVE-2026-17523 | HIGH | 7.8 | 0.1% | Jul 27, 2026 | A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vul... |
| CVE-2026-65894 | HIGH | 8.7 | — | Jul 27, 2026 | This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacke... |
| CVE-2026-65893 | HIGH | 7 | — | Jul 27, 2026 | This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An atta... |
| CVE-2026-64536 | HIGH | 8.1 | 0.2% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip(... |
| CVE-2026-64533 | HIGH | 7.8 | 0.2% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conver... |
| CVE-2026-64532 | HIGH | 7.8 | 0.2% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound NTFS_DE view.data_off in UpdateReco... |
| CVE-2026-64531 | HIGH | 7.8 | 0.1% | Jul 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action at... |
| CVE-2026-14837 | HIGH | 8.5 | 0.1% | Jul 27, 2026 | Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism... |
| CVE-2026-9830 | HIGH | 8.2 | — | Jul 27, 2026 | The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission cal... |
| CVE-2026-66412 | HIGH | 7.1 | 0.2% | Jul 27, 2026 | Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read mileston... |
| CVE-2026-14235 | HIGH | 7.5 | — | Jul 27, 2026 | The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session... |
| CVE-2026-13726 | HIGH | 7.1 | — | Jul 27, 2026 | The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the respons... |
| CVE-2026-13152 | HIGH | 8.1 | — | Jul 27, 2026 | The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registrat... |
| CVE-2026-12493 | HIGH | 7.5 | — | Jul 27, 2026 | The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved ext... |
| CVE-2026-12255 | HIGH | 8.1 | — | Jul 27, 2026 | The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration reques... |
| CVE-2026-15928 | HIGH | 8.2 | — | Jul 27, 2026 | XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in... |
| CVE-2026-57990 | HIGH | 7.4 | 0.9% | Jul 26, 2026 | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t... |
| CVE-2026-57989 | HIGH | 7.4 | 0.4% | Jul 26, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over ... |
| CVE-2026-17497 | HIGH | 8.3 | 0.5% | Jul 26, 2026 | NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with ar... |
| CVE-2026-17496 | HIGH | 8.1 | 0.3% | Jul 26, 2026 | NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into t... |
| CVE-2026-63720 | HIGH | 7.5 | 0.4% | Jul 26, 2026 | datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who contr... |
| CVE-2026-15962 | HIGH | 8.8 | 0.4% | Jul 26, 2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i... |
| CVE-2026-10681 | HIGH | 7 | 0.1% | Jul 25, 2026 | In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thre... |
| CVE-2026-64529 | HIGH | 7.8 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: qat - remove unused character device and IO... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now