2026 CVE Vulnerabilities
43,311 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8789 | HIGH | 8.1 | — | Jul 24, 2026 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2026-55732 | HIGH | 8.7 | 0.3% | Jul 24, 2026 | Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-R... |
| CVE-2026-55730 | HIGH | 8.7 | 0.4% | Jul 24, 2026 | Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenti... |
| CVE-2026-55729 | HIGH | 7.7 | 0.3% | Jul 24, 2026 | Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all pla... |
| CVE-2026-16801 | HIGH | 8.8 | 0.3% | Jul 24, 2026 | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2... |
| CVE-2026-16800 | HIGH | 8.8 | 0.3% | Jul 24, 2026 | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 20... |
| CVE-2026-12504 | HIGH | 8.4 | 0.1% | Jul 24, 2026 | Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-... |
| CVE-2026-12502 | HIGH | 8.4 | 0.1% | Jul 24, 2026 | Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, ... |
| CVE-2026-12496 | HIGH | 8.7 | 0.4% | Jul 24, 2026 | Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-I... |
| CVE-2026-9765 | HIGH | 7.1 | 0.3% | Jul 24, 2026 | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are ... |
| CVE-2026-66144 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the ... |
| CVE-2026-66143 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2... |
| CVE-2026-66142 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested s... |
| CVE-2026-45816 | HIGH | 7.5 | — | Jul 24, 2026 | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asser... |
| CVE-2026-45815 | HIGH | 7.5 | — | Jul 24, 2026 | Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_... |
| CVE-2026-45813 | HIGH | 8.8 | — | Jul 24, 2026 | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper valida... |
| CVE-2026-45811 | HIGH | 7.5 | — | Jul 24, 2026 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr... |
| CVE-2026-15810 | HIGH | 8.7 | 0.3% | Jul 24, 2026 | A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.6... |
| CVE-2026-15243 | HIGH | 7.4 | 0.2% | Jul 24, 2026 | Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches th... |
| CVE-2026-10610 | HIGH | 8.5 | 0.1% | Jul 24, 2026 | Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user. |
| CVE-2026-7483 | HIGH | 8.5 | 0.1% | Jul 24, 2026 | Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a... |
| CVE-2026-15401 | HIGH | 7.2 | 0.6% | Jul 24, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbf... |
| CVE-2026-10033 | HIGH | 7.3 | 0.3% | Jul 24, 2026 | The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,... |
| CVE-2026-49745 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ... |
| CVE-2026-49744 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now