2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73325 | HIGH | 7.8 | — | Aug 12, 2026 | Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers t... |
| CVE-2026-73293 | HIGH | 8.8 | — | Aug 12, 2026 | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ... |
| CVE-2026-73292 | HIGH | 8.3 | — | Aug 12, 2026 | Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accep... |
| CVE-2026-69105 | HIGH | 8.1 | — | Aug 12, 2026 | An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affe... |
| CVE-2026-68759 | HIGH | 7.2 | — | Aug 12, 2026 | A holder of a valid integration credential may impersonate other users under specific conditions. |
| CVE-2026-67260 | HIGH | 7.3 | — | Aug 12, 2026 | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the ... |
| CVE-2026-65941 | HIGH | 8.8 | — | Aug 12, 2026 | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affecte... |
| CVE-2026-65937 | HIGH | 8 | — | Aug 12, 2026 | In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject per... |
| CVE-2026-15803 | HIGH | 8.7 | — | Aug 12, 2026 | In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsin... |
| CVE-2026-73431 | HIGH | 8.8 | — | Aug 12, 2026 | Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Ac... |
| CVE-2026-73291 | HIGH | 7.1 | — | Aug 12, 2026 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'... |
| CVE-2026-73289 | HIGH | 8.1 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: ... |
| CVE-2026-73286 | HIGH | 8.1 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds a... |
| CVE-2026-73285 | HIGH | 7.5 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA a... |
| CVE-2026-73284 | HIGH | 8.8 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/servi... |
| CVE-2026-73264 | HIGH | 7.6 | — | Aug 12, 2026 | Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration acce... |
| CVE-2026-68757 | HIGH | 7.5 | — | Aug 12, 2026 | A user with access to a valid SAML response may impersonate another user under specific conditions. |
| CVE-2026-68752 | HIGH | 7.2 | — | Aug 12, 2026 | A Project Resource Manager may gain broader administrative privileges under specific conditions. |
| CVE-2026-66375 | HIGH | 8.1 | — | Aug 12, 2026 | A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific... |
| CVE-2026-14478 | HIGH | 7.8 | — | Aug 12, 2026 | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to in... |
| CVE-2026-47231 | HIGH | 8.1 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c... |
| CVE-2026-70468 | HIGH | 8.1 | — | Aug 12, 2026 | A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.... |
| CVE-2026-57858 | HIGH | 8.9 | — | Aug 12, 2026 | Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagMa... |
| CVE-2026-53996 | HIGH | 7.3 | — | Aug 12, 2026 | NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unpr... |
| CVE-2026-70465 | HIGH | 8.1 | — | Aug 12, 2026 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now