2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66321 | CRITICAL | 9.6 | 0.9% | Aug 4, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-18686 | CRITICAL | 9.8 | 2.6% | Aug 4, 2026 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of ... |
| CVE-2026-18685 | CRITICAL | 9.8 | 2.0% | Aug 4, 2026 | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the... |
| CVE-2026-48333 | CRITICAL | 9.8 | 0.5% | Aug 3, 2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege esca... |
| CVE-2026-48331 | CRITICAL | 10 | 0.5% | Aug 3, 2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv... |
| CVE-2026-48330 | CRITICAL | 10 | 0.7% | Aug 3, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
| CVE-2026-48326 | CRITICAL | 9.9 | 0.5% | Aug 3, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
| CVE-2026-48323 | CRITICAL | 10 | 0.6% | Aug 3, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vul... |
| CVE-2026-48317 | CRITICAL | 9.6 | 0.5% | Aug 3, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eva... |
| CVE-2026-18684 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the f... |
| CVE-2026-18667 | CRITICAL | 9.6 | 0.4% | Aug 3, 2026 | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an... |
| CVE-2026-46713 | CRITICAL | 9.2 | 0.2% | Aug 3, 2026 | Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a... |
| CVE-2026-69240 | CRITICAL | 9.8 | 0.3% | Aug 3, 2026 | Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracl... |
| CVE-2026-52102 | CRITICAL | 9.8 | 0.6% | Aug 3, 2026 | An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe... |
| CVE-2026-51775 | CRITICAL | 9.8 | 0.1% | Aug 3, 2026 | SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicati... |
| CVE-2026-51190 | CRITICAL | 9.8 | 0.5% | Aug 3, 2026 | The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spaw... |
| CVE-2026-48063 | CRITICAL | 9.3 | 0.2% | Aug 3, 2026 | Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baile... |
| CVE-2026-68980 | CRITICAL | 9.1 | 0.3% | Aug 3, 2026 | Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts throu... |
| CVE-2026-68979 | CRITICAL | 9.8 | 0.4% | Aug 3, 2026 | Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization... |
| CVE-2026-67598 | CRITICAL | 9.1 | — | Aug 3, 2026 | Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all... |
| CVE-2026-48031 | CRITICAL | 9.1 | — | Aug 3, 2026 | go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202... |
| CVE-2026-38447 | CRITICAL | 9.8 | — | Aug 3, 2026 | osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with ... |
| CVE-2026-18616 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of... |
| CVE-2026-18615 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate... |
| CVE-2026-18614 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now