2026 CVE Vulnerabilities
43,225 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73140 | MEDIUM | 5.3 | 0.3% | Aug 11, 2026 | Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report ex... |
| CVE-2026-19519 | MEDIUM | 4.3 | 0.3% | Aug 11, 2026 | A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked... |
| CVE-2026-19518 | MEDIUM | 6.5 | 0.2% | Aug 11, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipu... |
| CVE-2026-19517 | MEDIUM | 6.5 | 0.2% | Aug 11, 2026 | Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit... |
| CVE-2026-19391 | MEDIUM | 6.5 | 0.2% | Aug 11, 2026 | A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the ... |
| CVE-2026-8158 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to ... |
| CVE-2026-6505 | MEDIUM | 5.1 | 0.1% | Aug 11, 2026 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv... |
| CVE-2026-6181 | MEDIUM | 5.9 | 0.3% | Aug 11, 2026 | The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after... |
| CVE-2026-5304 | MEDIUM | 5.7 | 0.2% | Aug 11, 2026 | An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerabil... |
| CVE-2026-5303 | MEDIUM | 5.7 | 0.2% | Aug 11, 2026 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv... |
| CVE-2026-18348 | MEDIUM | 4.1 | 0.2% | Aug 11, 2026 | Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst... |
| CVE-2026-14549 | MEDIUM | 4.3 | 0.1% | Aug 11, 2026 | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ... |
| CVE-2026-14548 | MEDIUM | 6.5 | 0.1% | Aug 11, 2026 | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ... |
| CVE-2026-12052 | MEDIUM | 5.2 | 0.2% | Aug 11, 2026 | The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.... |
| CVE-2026-12051 | MEDIUM | 4.6 | 0.2% | Aug 11, 2026 | The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der... |
| CVE-2026-11894 | MEDIUM | 5.9 | 0.2% | Aug 11, 2026 | The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the... |
| CVE-2026-16974 | MEDIUM | 6.4 | 0.2% | Aug 11, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2026-11893 | MEDIUM | 5.9 | 0.2% | Aug 11, 2026 | The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo... |
| CVE-2026-24330 | MEDIUM | 6.5 | 0.3% | Aug 11, 2026 | A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali... |
| CVE-2026-24329 | MEDIUM | 4.9 | 0.3% | Aug 11, 2026 | A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i... |
| CVE-2026-66779 | MEDIUM | 6.3 | 0.2% | Aug 11, 2026 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker co... |
| CVE-2026-66778 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A... |
| CVE-2026-66777 | MEDIUM | 5.9 | 0.3% | Aug 11, 2026 | SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D... |
| CVE-2026-66776 | MEDIUM | 5.9 | 0.1% | Aug 11, 2026 | SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec... |
| CVE-2026-66775 | MEDIUM | 4.3 | 0.1% | Aug 11, 2026 | SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now