2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47705 | CRITICAL | 9.6 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. ... |
| CVE-2026-27302 | CRITICAL | 10 | — | Aug 11, 2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code... |
| CVE-2026-71384 | CRITICAL | 9.6 | 0.2% | Aug 11, 2026 | is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul... |
| CVE-2026-70306 | CRITICAL | 9.3 | — | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-65791 | CRITICAL | 9.8 | — | Aug 11, 2026 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ... |
| CVE-2026-62893 | CRITICAL | 9.8 | — | Aug 11, 2026 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |
| CVE-2026-62878 | CRITICAL | 9.8 | 0.9% | Aug 11, 2026 | Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. |
| CVE-2026-62815 | CRITICAL | 9.8 | — | Aug 11, 2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. |
| CVE-2026-59124 | CRITICAL | 9.8 | — | Aug 11, 2026 | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to ... |
| CVE-2026-50516 | CRITICAL | 9.4 | — | Aug 11, 2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el... |
| CVE-2026-48362 | CRITICAL | 10 | — | Aug 11, 2026 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') ... |
| CVE-2026-12571 | CRITICAL | 9.8 | — | Aug 11, 2026 | An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. |
| CVE-2026-73080 | CRITICAL | 9.3 | — | Aug 11, 2026 | SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_re... |
| CVE-2026-73069 | CRITICAL | 9.1 | — | Aug 11, 2026 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace ad... |
| CVE-2026-72920 | CRITICAL | 9.8 | — | Aug 11, 2026 | SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s... |
| CVE-2026-47702 | CRITICAL | 9.1 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the bu... |
| CVE-2026-17061 | CRITICAL | 10 | — | Aug 11, 2026 | A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2... |
| CVE-2026-48056 | CRITICAL | 10 | — | Aug 11, 2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro... |
| CVE-2026-48046 | CRITICAL | 9.3 | — | Aug 11, 2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contai... |
| CVE-2026-46670 | CRITICAL | 9.8 | — | Aug 11, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-imp... |
| CVE-2026-72785 | CRITICAL | 9.3 | — | Aug 11, 2026 | Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only ... |
| CVE-2026-72748 | CRITICAL | 9.1 | — | Aug 11, 2026 | AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that a... |
| CVE-2026-58115 | CRITICAL | 10 | — | Aug 11, 2026 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In... |
| CVE-2026-18972 | CRITICAL | 9.6 | — | Aug 11, 2026 | An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-M... |
| CVE-2026-72603 | CRITICAL | 9.9 | — | Aug 11, 2026 | An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now