2026 CVE Vulnerabilities
43,098 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-68432 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns fo... |
| CVE-2026-68431 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requ... |
| CVE-2026-68430 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx8: drop unecessary BUG_ON() There's ... |
| CVE-2026-68429 | — | — | — | Aug 12, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Handle torn-down topology gracefully in... |
| CVE-2026-73250 | MEDIUM | 5.4 | — | Aug 11, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer... |
| CVE-2026-73249 | HIGH | 7.5 | — | Aug 11, 2026 | calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{librar... |
| CVE-2026-73248 | HIGH | 8.5 | — | Aug 11, 2026 | calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a ... |
| CVE-2026-73247 | HIGH | 8.6 | — | Aug 11, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/cor... |
| CVE-2026-73246 | HIGH | 7.5 | — | Aug 11, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kest... |
| CVE-2026-73245 | MEDIUM | 6.5 | — | Aug 11, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/appli... |
| CVE-2026-68067 | CRITICAL | 9.8 | — | Aug 11, 2026 | The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active... |
| CVE-2026-67568 | CRITICAL | 9.3 | — | Aug 11, 2026 | The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from int... |
| CVE-2026-67558 | HIGH | 8.2 | 0.2% | Aug 11, 2026 | The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match aga... |
| CVE-2026-66875 | HIGH | 8.8 | — | Aug 11, 2026 | In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range... |
| CVE-2026-66340 | MEDIUM | 6.9 | — | Aug 11, 2026 | The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout ... |
| CVE-2026-66098 | HIGH | 7.1 | — | Aug 11, 2026 | The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the d... |
| CVE-2026-64934 | MEDIUM | 5.3 | — | Aug 11, 2026 | The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho... |
| CVE-2026-5917 | CRITICAL | 9.6 | — | Aug 11, 2026 | libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command inj... |
| CVE-2026-29036 | HIGH | 7.5 | — | Aug 11, 2026 | cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointe... |
| CVE-2026-19560 | HIGH | 8.8 | — | Aug 11, 2026 | Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-19559 | — | — | — | Aug 11, 2026 | Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code insi... |
| CVE-2026-19558 | HIGH | 7.5 | — | Aug 11, 2026 | Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to instal... |
| CVE-2026-19557 | HIGH | 8.3 | — | Aug 11, 2026 | Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised... |
| CVE-2026-19556 | HIGH | 8.8 | — | Aug 11, 2026 | Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside... |
| CVE-2026-18710 | HIGH | 8.2 | — | Aug 11, 2026 | A MongoDB driver component could write sensitive configuration information, including a credential used for outbound net... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now