2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6727 | MEDIUM | 5.9 | 0.2% | Aug 11, 2026 | A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with a... |
| CVE-2026-56720 | MEDIUM | 5.3 | — | Aug 11, 2026 | CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that ... |
| CVE-2026-53414 | MEDIUM | 6.5 | — | Aug 11, 2026 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic... |
| CVE-2026-19078 | MEDIUM | 4.3 | — | Aug 11, 2026 | A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the... |
| CVE-2026-18638 | MEDIUM | 6.5 | — | Aug 11, 2026 | Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces... |
| CVE-2026-14180 | MEDIUM | 5.3 | — | Aug 11, 2026 | A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han... |
| CVE-2026-11814 | MEDIUM | 4.9 | 0.8% | Aug 11, 2026 | A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to in... |
| CVE-2026-11739 | MEDIUM | 4.9 | — | Aug 11, 2026 | A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with... |
| CVE-2026-11738 | MEDIUM | 4.3 | — | Aug 11, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t... |
| CVE-2026-11737 | MEDIUM | 4.3 | — | Aug 11, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected ... |
| CVE-2026-73067 | MEDIUM | 6.7 | — | Aug 11, 2026 | Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init ca... |
| CVE-2026-73066 | MEDIUM | 6.8 | — | Aug 11, 2026 | Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesse... |
| CVE-2026-72925 | MEDIUM | 6.1 | — | Aug 11, 2026 | SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi... |
| CVE-2026-18636 | MEDIUM | 6.8 | — | Aug 11, 2026 | The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr... |
| CVE-2026-17535 | MEDIUM | 6.2 | — | Aug 11, 2026 | Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by... |
| CVE-2026-73210 | MEDIUM | 5.1 | 0.4% | Aug 11, 2026 | A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup o... |
| CVE-2026-19434 | MEDIUM | 5.1 | 0.3% | Aug 11, 2026 | Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute ar... |
| CVE-2026-72784 | MEDIUM | 6.9 | — | Aug 11, 2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne... |
| CVE-2026-72783 | MEDIUM | 6.2 | — | Aug 11, 2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakne... |
| CVE-2026-72775 | MEDIUM | 5.8 | — | Aug 11, 2026 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interp... |
| CVE-2026-72773 | MEDIUM | 4.9 | — | Aug 11, 2026 | n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (searc... |
| CVE-2026-72769 | MEDIUM | 6.1 | — | Aug 11, 2026 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An aut... |
| CVE-2026-72768 | MEDIUM | 6.4 | — | Aug 11, 2026 | n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node ... |
| CVE-2026-72764 | MEDIUM | 5.8 | — | Aug 11, 2026 | n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (... |
| CVE-2026-72750 | MEDIUM | 5.3 | — | Aug 11, 2026 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query ope... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now