2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72744 | MEDIUM | 6.9 | — | Aug 11, 2026 | Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the ... |
| CVE-2026-59693 | MEDIUM | 5.3 | — | Aug 11, 2026 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.... |
| CVE-2026-72610 | MEDIUM | 4.3 | — | Aug 11, 2026 | A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta... |
| CVE-2026-72608 | MEDIUM | 6.5 | — | Aug 11, 2026 | A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta... |
| CVE-2026-72604 | MEDIUM | 6.5 | — | Aug 11, 2026 | A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete ar... |
| CVE-2026-72598 | MEDIUM | 6.5 | — | Aug 11, 2026 | A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the se... |
| CVE-2026-72597 | MEDIUM | 6.5 | — | Aug 11, 2026 | A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with ... |
| CVE-2026-72560 | MEDIUM | 6.5 | — | Aug 11, 2026 | A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTI... |
| CVE-2026-72559 | MEDIUM | 5.4 | — | Aug 11, 2026 | A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent... |
| CVE-2026-72554 | MEDIUM | 6.5 | — | Aug 11, 2026 | A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer ... |
| CVE-2026-72553 | MEDIUM | 5.4 | — | Aug 11, 2026 | A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persisten... |
| CVE-2026-72549 | MEDIUM | 5.3 | — | Aug 11, 2026 | An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ... |
| CVE-2026-72542 | MEDIUM | 5.4 | — | Aug 11, 2026 | A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write ... |
| CVE-2026-72541 | MEDIUM | 6.5 | — | Aug 11, 2026 | A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe... |
| CVE-2026-72540 | MEDIUM | 4.3 | — | Aug 11, 2026 | An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid prev... |
| CVE-2026-72539 | MEDIUM | 6.5 | — | Aug 11, 2026 | An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem... |
| CVE-2026-73162 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /acco... |
| CVE-2026-33922 | MEDIUM | 6.8 | 0.2% | Aug 11, 2026 | A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to in... |
| CVE-2026-33921 | MEDIUM | 5.2 | 0.1% | Aug 11, 2026 | The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver ... |
| CVE-2026-73161 | MEDIUM | 5.1 | 0.2% | Aug 11, 2026 | Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feat... |
| CVE-2026-73159 | MEDIUM | 5.1 | 0.2% | Aug 11, 2026 | Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's ... |
| CVE-2026-73158 | MEDIUM | 5.1 | 0.2% | Aug 11, 2026 | Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can cont... |
| CVE-2026-71218 | MEDIUM | 5.3 | 0.3% | Aug 11, 2026 | A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function,... |
| CVE-2026-73156 | MEDIUM | 5.3 | 0.3% | Aug 11, 2026 | Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap t... |
| CVE-2026-73155 | MEDIUM | 5.3 | 0.3% | Aug 11, 2026 | Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now