2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-69256 | CRITICAL | 9.4 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent no... |
| CVE-2026-69255 | CRITICAL | 9.2 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in... |
| CVE-2026-64633 | CRITICAL | 10 | — | Aug 4, 2026 | A vulnerability allowing remote unauthenticated code execution on the agent host. |
| CVE-2026-63456 | CRITICAL | 9.8 | 0.4% | Aug 4, 2026 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated ... |
| CVE-2026-63455 | CRITICAL | 9.8 | 0.4% | Aug 4, 2026 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated ... |
| CVE-2026-58073 | CRITICAL | 9.5 | — | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an... |
| CVE-2026-58072 | CRITICAL | 9 | — | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead... |
| CVE-2026-69254 | CRITICAL | 9.4 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScri... |
| CVE-2026-69253 | CRITICAL | 9 | 0.3% | Aug 4, 2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1... |
| CVE-2026-69110 | CRITICAL | 9.3 | — | Aug 4, 2026 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attacker... |
| CVE-2026-69098 | CRITICAL | 9.8 | 0.5% | Aug 4, 2026 | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows ... |
| CVE-2026-25289 | CRITICAL | 9.6 | 0.2% | Aug 4, 2026 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with inv... |
| CVE-2026-18801 | CRITICAL | 9.3 | — | Aug 4, 2026 | OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution ... |
| CVE-2026-69251 | CRITICAL | 9 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record ... |
| CVE-2026-61515 | CRITICAL | 9.8 | — | Aug 4, 2026 | Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allo... |
| CVE-2026-61514 | CRITICAL | 9.8 | — | Aug 4, 2026 | Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthent... |
| CVE-2026-10050 | CRITICAL | 9.1 | 0.4% | Aug 4, 2026 | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. Th... |
| CVE-2026-15721 | CRITICAL | 9.8 | — | Aug 4, 2026 | Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Dig... |
| CVE-2026-14804 | CRITICAL | 9.1 | — | Aug 4, 2026 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Hu... |
| CVE-2026-14175 | CRITICAL | 9.8 | — | Aug 4, 2026 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIS... |
| CVE-2026-18754 | CRITICAL | 9.1 | — | Aug 4, 2026 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio... |
| CVE-2026-18753 | CRITICAL | 9.1 | — | Aug 4, 2026 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio... |
| CVE-2026-64564 | CRITICAL | 9.8 | 0.2% | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-... |
| CVE-2026-16618 | CRITICAL | 9.8 | 0.2% | Aug 4, 2026 | The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file conten... |
| CVE-2026-15958 | CRITICAL | 9.3 | 0.1% | Aug 4, 2026 | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now