2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11809 | LOW | 3.7 | 0.3% | Aug 10, 2026 | The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z... |
| CVE-2026-6368 | LOW | 2.1 | — | Aug 10, 2026 | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return inva... |
| CVE-2026-72729 | LOW | 2 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-loca... |
| CVE-2026-18503 | LOW | 2.4 | 0.1% | Aug 10, 2026 | Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume si... |
| CVE-2026-64941 | LOW | 2.1 | — | Aug 10, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attack... |
| CVE-2026-17016 | LOW | 3.7 | 0.1% | Aug 10, 2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amoun... |
| CVE-2026-14211 | LOW | 3.8 | 0.1% | Aug 10, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated empl... |
| CVE-2026-12971 | LOW | 2.2 | 0.1% | Aug 10, 2026 | The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowi... |
| CVE-2026-19382 | LOW | 2.3 | — | Aug 10, 2026 | A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan... |
| CVE-2026-19380 | LOW | 2.3 | 0.1% | Aug 10, 2026 | A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the... |
| CVE-2026-12372 | LOW | 3.7 | — | Aug 9, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. Th... |
| CVE-2026-70395 | LOW | 2.1 | 0.1% | Aug 9, 2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to f... |
| CVE-2026-19361 | LOW | 3.7 | — | Aug 9, 2026 | A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode o... |
| CVE-2026-19352 | LOW | 3.1 | 0.2% | Aug 9, 2026 | A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality o... |
| CVE-2026-17011 | LOW | 3.8 | 0.1% | Aug 9, 2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo... |
| CVE-2026-16957 | LOW | 2.7 | 0.1% | Aug 9, 2026 | The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed ... |
| CVE-2026-19324 | LOW | 3.3 | 0.1% | Aug 9, 2026 | A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by th... |
| CVE-2026-11742 | LOW | 3.6 | 0.1% | Aug 7, 2026 | The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read... |
| CVE-2026-19245 | LOW | 3.3 | 0.1% | Aug 7, 2026 | A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of th... |
| CVE-2026-71849 | LOW | 3.7 | 0.2% | Aug 7, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy H... |
| CVE-2026-66000 | LOW | 2.3 | — | Aug 7, 2026 | Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation... |
| CVE-2026-19230 | LOW | 3.5 | — | Aug 7, 2026 | A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /soci... |
| CVE-2026-17435 | LOW | 2.5 | 0.2% | Aug 7, 2026 | File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When th... |
| CVE-2026-19209 | LOW | 3.5 | — | Aug 7, 2026 | A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file... |
| CVE-2026-19208 | LOW | 3.7 | — | Aug 7, 2026 | A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now