2026 CVE Vulnerabilities
43,347 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66143 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2... |
| CVE-2026-66142 | HIGH | 7.5 | 0.3% | Jul 24, 2026 | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested s... |
| CVE-2026-45816 | HIGH | 7.5 | — | Jul 24, 2026 | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asser... |
| CVE-2026-45815 | HIGH | 7.5 | — | Jul 24, 2026 | Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_... |
| CVE-2026-45813 | HIGH | 8.8 | — | Jul 24, 2026 | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper valida... |
| CVE-2026-45811 | HIGH | 7.5 | — | Jul 24, 2026 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr... |
| CVE-2026-15810 | HIGH | 8.7 | 0.3% | Jul 24, 2026 | A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.6... |
| CVE-2026-15243 | HIGH | 7.4 | 0.2% | Jul 24, 2026 | Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches th... |
| CVE-2026-10610 | HIGH | 8.5 | 0.1% | Jul 24, 2026 | Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user. |
| CVE-2026-7483 | HIGH | 8.5 | 0.1% | Jul 24, 2026 | Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a... |
| CVE-2026-15401 | HIGH | 7.2 | 0.6% | Jul 24, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbf... |
| CVE-2026-10033 | HIGH | 7.3 | 0.3% | Jul 24, 2026 | The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,... |
| CVE-2026-49745 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ... |
| CVE-2026-49744 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ... |
| CVE-2026-49743 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of... |
| CVE-2026-16519 | HIGH | 7.3 | 0.1% | Jul 24, 2026 | A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on... |
| CVE-2026-14603 | HIGH | 7.5 | 0.1% | Jul 24, 2026 | The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint... |
| CVE-2026-14172 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without ... |
| CVE-2026-12981 | HIGH | 7.5 | 0.2% | Jul 24, 2026 | The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user pas... |
| CVE-2026-12497 | HIGH | 7.5 | 0.1% | Jul 24, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2026-16870 | HIGH | 8.8 | 0.4% | Jul 24, 2026 | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execut... |
| CVE-2026-66141 | HIGH | 7.4 | 0.1% | Jul 24, 2026 | Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled. |
| CVE-2026-66140 | HIGH | 8.4 | 0.3% | Jul 24, 2026 | Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privilege... |
| CVE-2026-66138 | HIGH | 7.2 | 0.4% | Jul 24, 2026 | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code ... |
| CVE-2026-12736 | HIGH | 8 | 0.3% | Jul 24, 2026 | The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now