2026 CVE Vulnerabilities
43,896 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52879 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-mess... |
| CVE-2026-52878 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a... |
| CVE-2026-49343 | MEDIUM | 5.9 | 0.3% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie... |
| CVE-2026-48122 | MEDIUM | 5.4 | 0.1% | Aug 7, 2026 | Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP... |
| CVE-2026-48120 | HIGH | 8.6 | 0.1% | Aug 7, 2026 | Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be ... |
| CVE-2026-48047 | MEDIUM | 5.9 | 0.3% | Aug 7, 2026 | XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to ... |
| CVE-2026-48026 | HIGH | 8.7 | 0.2% | Aug 7, 2026 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of th... |
| CVE-2026-47249 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling... |
| CVE-2026-47127 | MEDIUM | 6.5 | 0.2% | Aug 7, 2026 | Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR... |
| CVE-2026-46409 | CRITICAL | 9.6 | 0.4% | Aug 7, 2026 | OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to v... |
| CVE-2026-64676 | MEDIUM | 5.7 | 0.1% | Aug 7, 2026 | Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In ... |
| CVE-2026-58262 | HIGH | 7.1 | 0.1% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification cou... |
| CVE-2026-48170 | CRITICAL | 9.1 | 0.3% | Aug 7, 2026 | `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM ... |
| CVE-2026-48169 | HIGH | 8.8 | 0.3% | Aug 7, 2026 | PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization fa... |
| CVE-2026-47243 | CRITICAL | 9.2 | 0.2% | Aug 7, 2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2026-46405 | MEDIUM | 5.3 | 0.4% | Aug 7, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth m... |
| CVE-2026-45808 | HIGH | 7.1 | 0.3% | Aug 7, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide... |
| CVE-2026-11743 | MEDIUM | 6.6 | 0.1% | Aug 7, 2026 | The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length o... |
| CVE-2026-11742 | LOW | 3.6 | 0.1% | Aug 7, 2026 | The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read... |
| CVE-2026-9031 | MEDIUM | 6.8 | 0.2% | Aug 7, 2026 | An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied da... |
| CVE-2026-9030 | MEDIUM | 6.8 | 0.1% | Aug 7, 2026 | A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction han... |
| CVE-2026-71381 | MEDIUM | 4 | 0.2% | Aug 7, 2026 | Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a... |
| CVE-2026-70624 | — | — | — | Aug 7, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-70623 | — | — | — | Aug 7, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-69207 | MEDIUM | 5.3 | 0.7% | Aug 7, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in COR... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now