2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73432 | MEDIUM | 5.1 | — | Aug 12, 2026 | Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization ... |
| CVE-2026-73431 | HIGH | 8.8 | — | Aug 12, 2026 | Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Ac... |
| CVE-2026-73405 | MEDIUM | 5.3 | — | Aug 12, 2026 | An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to S... |
| CVE-2026-73374 | MEDIUM | 6.1 | — | Aug 12, 2026 | A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter ... |
| CVE-2026-73291 | HIGH | 7.1 | — | Aug 12, 2026 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'... |
| CVE-2026-73290 | MEDIUM | 5.3 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions req... |
| CVE-2026-73289 | HIGH | 8.1 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: ... |
| CVE-2026-73288 | MEDIUM | 6.1 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crat... |
| CVE-2026-73287 | MEDIUM | 5.4 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriv... |
| CVE-2026-73286 | HIGH | 8.1 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds a... |
| CVE-2026-73285 | HIGH | 7.5 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA a... |
| CVE-2026-73284 | HIGH | 8.8 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/servi... |
| CVE-2026-73265 | MEDIUM | 6.5 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, Co... |
| CVE-2026-73264 | HIGH | 7.6 | — | Aug 12, 2026 | Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration acce... |
| CVE-2026-73263 | CRITICAL | 9.9 | — | Aug 12, 2026 | Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_conte... |
| CVE-2026-73262 | MEDIUM | 5.4 | — | Aug 12, 2026 | Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.... |
| CVE-2026-68760 | MEDIUM | 5.3 | — | Aug 12, 2026 | An unauthenticated user may bypass authentication under specific cache conditions. |
| CVE-2026-68757 | HIGH | 7.5 | — | Aug 12, 2026 | A user with access to a valid SAML response may impersonate another user under specific conditions. |
| CVE-2026-68756 | MEDIUM | 6.6 | — | Aug 12, 2026 | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. |
| CVE-2026-68755 | MEDIUM | 4.3 | — | Aug 12, 2026 | A bundle writer may create misleading release promotion information under specific conditions. |
| CVE-2026-68754 | MEDIUM | 6.5 | — | Aug 12, 2026 | A repository publisher without delete permission may modify protected package content under specific conditions. |
| CVE-2026-68753 | MEDIUM | 5.3 | — | Aug 12, 2026 | An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in... |
| CVE-2026-68752 | HIGH | 7.2 | — | Aug 12, 2026 | A Project Resource Manager may gain broader administrative privileges under specific conditions. |
| CVE-2026-67287 | MEDIUM | 6.3 | — | Aug 12, 2026 | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated att... |
| CVE-2026-67286 | MEDIUM | 6.3 | — | Aug 12, 2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now