2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19556 | HIGH | 8.8 | — | Aug 11, 2026 | Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside... |
| CVE-2026-18710 | HIGH | 8.2 | — | Aug 11, 2026 | A MongoDB driver component could write sensitive configuration information, including a credential used for outbound net... |
| CVE-2026-71290 | CRITICAL | 9.1 | 0.1% | Aug 11, 2026 | Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolic... |
| CVE-2026-66832 | MEDIUM | 6.9 | — | Aug 11, 2026 | When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app... |
| CVE-2026-66154 | HIGH | 8.3 | 0.1% | Aug 11, 2026 | An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1... |
| CVE-2026-66150 | HIGH | 7.8 | — | Aug 11, 2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows... |
| CVE-2026-66149 | HIGH | 7.8 | — | Aug 11, 2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows... |
| CVE-2026-66148 | MEDIUM | 6.3 | — | Aug 11, 2026 | An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.10... |
| CVE-2026-66147 | CRITICAL | 9.4 | 1.0% | Aug 11, 2026 | An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier... |
| CVE-2026-63177 | HIGH | 7.1 | — | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng... |
| CVE-2026-63134 | MEDIUM | 5.4 | — | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w... |
| CVE-2026-63133 | MEDIUM | 6.5 | — | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives... |
| CVE-2026-55676 | HIGH | 8.8 | — | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `P... |
| CVE-2026-48765 | CRITICAL | 9.9 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspa... |
| CVE-2026-48763 | HIGH | 8.2 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t... |
| CVE-2026-48762 | MEDIUM | 5.4 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u... |
| CVE-2026-29035 | HIGH | 8.3 | 0.5% | Aug 11, 2026 | CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that... |
| CVE-2026-19579 | MEDIUM | 5.4 | — | Aug 11, 2026 | Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request ... |
| CVE-2026-19550 | MEDIUM | 4.3 | — | Aug 11, 2026 | A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath... |
| CVE-2026-18634 | HIGH | 8.4 | 0.3% | Aug 11, 2026 | An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (B... |
| CVE-2026-15606 | HIGH | 8.8 | 0.3% | Aug 11, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i... |
| CVE-2026-14863 | HIGH | 8.8 | — | Aug 11, 2026 | FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated at... |
| CVE-2026-73283 | LOW | 2.5 | — | Aug 11, 2026 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar... |
| CVE-2026-73282 | MEDIUM | 4.8 | — | Aug 11, 2026 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat... |
| CVE-2026-73281 | LOW | 3.5 | — | Aug 11, 2026 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now