2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73244 | MEDIUM | 5.3 | — | Aug 11, 2026 | kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /li... |
| CVE-2026-73243 | MEDIUM | 5.8 | — | Aug 11, 2026 | kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /add... |
| CVE-2026-73242 | HIGH | 8.3 | — | Aug 11, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos... |
| CVE-2026-73241 | HIGH | 8.3 | — | Aug 11, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreer... |
| CVE-2026-73235 | MEDIUM | 6.1 | — | Aug 11, 2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constru... |
| CVE-2026-73234 | HIGH | 7.8 | — | Aug 11, 2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() i... |
| CVE-2026-73233 | HIGH | 8.5 | — | Aug 11, 2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint t... |
| CVE-2026-73232 | HIGH | 7.5 | — | Aug 11, 2026 | ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory... |
| CVE-2026-73231 | HIGH | 7.8 | — | Aug 11, 2026 | Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method ... |
| CVE-2026-73230 | MEDIUM | 5.9 | — | Aug 11, 2026 | Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version... |
| CVE-2026-73229 | MEDIUM | 4.3 | — | Aug 11, 2026 | Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's... |
| CVE-2026-73036 | MEDIUM | 4.6 | — | Aug 11, 2026 | Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt... |
| CVE-2026-73034 | CRITICAL | 9.8 | — | Aug 11, 2026 | DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary f... |
| CVE-2026-73032 | CRITICAL | 9.6 | — | Aug 11, 2026 | PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav... |
| CVE-2026-73031 | HIGH | 8.7 | — | Aug 11, 2026 | telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary J... |
| CVE-2026-71845 | MEDIUM | 6.3 | 0.2% | Aug 11, 2026 | A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes... |
| CVE-2026-71475 | MEDIUM | 5 | — | Aug 11, 2026 | A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data ... |
| CVE-2026-71474 | MEDIUM | 6.3 | — | Aug 11, 2026 | A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, whic... |
| CVE-2026-71468 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly ... |
| CVE-2026-71467 | HIGH | 7.5 | — | Aug 11, 2026 | A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authent... |
| CVE-2026-70339 | MEDIUM | 5.4 | — | Aug 11, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-66146 | MEDIUM | 6.1 | — | Aug 11, 2026 | Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions ... |
| CVE-2026-66145 | CRITICAL | 9.1 | 0.4% | Aug 11, 2026 | An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version... |
| CVE-2026-65655 | LOW | 2.3 | — | Aug 11, 2026 | When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to ... |
| CVE-2026-48813 | HIGH | 8.7 | — | Aug 11, 2026 | Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now