2026 CVE Vulnerabilities
46,924 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19546 | HIGH | 8.8 | 0.3% | Aug 11, 2026 | A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed S... |
| CVE-2026-19078 | MEDIUM | 4.3 | 0.3% | Aug 11, 2026 | A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the... |
| CVE-2026-18640 | HIGH | 7.1 | — | Aug 11, 2026 | The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT perm... |
| CVE-2026-18639 | HIGH | 7.3 | — | Aug 11, 2026 | When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, s... |
| CVE-2026-18638 | MEDIUM | 6.5 | — | Aug 11, 2026 | Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces... |
| CVE-2026-14180 | MEDIUM | 5.3 | 0.4% | Aug 11, 2026 | A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han... |
| CVE-2026-11814 | MEDIUM | 4.9 | 0.8% | Aug 11, 2026 | A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to in... |
| CVE-2026-11739 | MEDIUM | 4.9 | — | Aug 11, 2026 | A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with... |
| CVE-2026-11738 | MEDIUM | 4.3 | — | Aug 11, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t... |
| CVE-2026-11737 | MEDIUM | 4.3 | — | Aug 11, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected ... |
| CVE-2026-11736 | LOW | 1.9 | — | Aug 11, 2026 | A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make ... |
| CVE-2026-11735 | LOW | 1.9 | — | Aug 11, 2026 | A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to ma... |
| CVE-2026-11734 | LOW | 1.1 | — | Aug 11, 2026 | A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de... |
| CVE-2026-11733 | LOW | 1.1 | — | Aug 11, 2026 | A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the ... |
| CVE-2026-73067 | MEDIUM | 6.7 | — | Aug 11, 2026 | Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init ca... |
| CVE-2026-73066 | MEDIUM | 6.8 | — | Aug 11, 2026 | Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesse... |
| CVE-2026-72925 | MEDIUM | 6.1 | — | Aug 11, 2026 | SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi... |
| CVE-2026-72922 | HIGH | 8.2 | 0.3% | Aug 11, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-72921 | HIGH | 8.1 | 0.2% | Aug 11, 2026 | SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth... |
| CVE-2026-72920 | CRITICAL | 9.8 | — | Aug 11, 2026 | SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s... |
| CVE-2026-47702 | CRITICAL | 9.1 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the bu... |
| CVE-2026-18860 | HIGH | 8.7 | — | Aug 11, 2026 | Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can cr... |
| CVE-2026-18636 | MEDIUM | 6.8 | — | Aug 11, 2026 | The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr... |
| CVE-2026-18635 | HIGH | 7.2 | 0.3% | Aug 11, 2026 | Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able ... |
| CVE-2026-18129 | HIGH | 8.1 | — | Aug 11, 2026 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now