2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66382 | MEDIUM | 4.3 | — | Aug 12, 2026 | An authenticated user may write files outside the intended Artifactory work directory under specific conditions. |
| CVE-2026-66381 | MEDIUM | 5.3 | — | Aug 12, 2026 | A repository reader with cache-deploy permission may access content outside a configured upstream path under specific co... |
| CVE-2026-66380 | MEDIUM | 4.3 | — | Aug 12, 2026 | An authenticated user without repository read permission may access private OCI referrer metadata under specific conditi... |
| CVE-2026-66379 | MEDIUM | 4.3 | — | Aug 12, 2026 | An authenticated user may view private Puppet module metadata without repository read access. |
| CVE-2026-66378 | MEDIUM | 4.3 | — | Aug 12, 2026 | An authenticated user without repository read permission may access private NuGet metadata under specific conditions. |
| CVE-2026-66377 | MEDIUM | 5.3 | — | Aug 12, 2026 | An unauthenticated user may access restricted repository information under specific conditions. |
| CVE-2026-66376 | MEDIUM | 4.2 | — | Aug 12, 2026 | Credentials for a deleted user may remain valid for a short period under specific conditions. |
| CVE-2026-66375 | HIGH | 8.1 | — | Aug 12, 2026 | A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific... |
| CVE-2026-50561 | CRITICAL | 9.4 | — | Aug 12, 2026 | Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version ... |
| CVE-2026-49349 | MEDIUM | 6.8 | — | Aug 12, 2026 | regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert... |
| CVE-2026-49262 | LOW | 3 | — | Aug 12, 2026 | In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is ... |
| CVE-2026-47234 | MEDIUM | 4.4 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se... |
| CVE-2026-47233 | MEDIUM | 6.5 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `... |
| CVE-2026-18171 | MEDIUM | 5.7 | — | Aug 12, 2026 | Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the und... |
| CVE-2026-14479 | MEDIUM | 5.5 | — | Aug 12, 2026 | A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation ... |
| CVE-2026-14478 | HIGH | 7.8 | — | Aug 12, 2026 | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to in... |
| CVE-2026-67285 | CRITICAL | 9.2 | — | Aug 12, 2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An u... |
| CVE-2026-47232 | MEDIUM | 4.3 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modu... |
| CVE-2026-47231 | HIGH | 8.1 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c... |
| CVE-2026-47230 | MEDIUM | 6.5 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_re... |
| CVE-2026-47229 | MEDIUM | 5.4 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm... |
| CVE-2026-47228 | MEDIUM | 5.2 | — | Aug 12, 2026 | Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random pa... |
| CVE-2026-47227 | MEDIUM | 6.5 | — | Aug 12, 2026 | Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (... |
| CVE-2026-16999 | MEDIUM | 6.3 | — | Aug 12, 2026 | Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows S... |
| CVE-2026-71408 | MEDIUM | 5.3 | — | Aug 12, 2026 | A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now