2026 CVE Vulnerabilities
47,229 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72543 | HIGH | 7.5 | — | Aug 11, 2026 | An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote ... |
| CVE-2026-72542 | MEDIUM | 5.4 | — | Aug 11, 2026 | A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write ... |
| CVE-2026-72541 | MEDIUM | 6.5 | — | Aug 11, 2026 | A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe... |
| CVE-2026-72540 | — | — | 0.2% | Aug 11, 2026 | Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid. |
| CVE-2026-72539 | MEDIUM | 6.5 | — | Aug 11, 2026 | An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem... |
| CVE-2026-72538 | HIGH | 8.8 | — | Aug 11, 2026 | An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code... |
| CVE-2026-72537 | HIGH | 8.8 | — | Aug 11, 2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s... |
| CVE-2026-72536 | HIGH | 8.6 | — | Aug 11, 2026 | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mani... |
| CVE-2026-72535 | HIGH | 8.6 | — | Aug 11, 2026 | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint... |
| CVE-2026-72534 | HIGH | 8.8 | — | Aug 11, 2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s... |
| CVE-2026-72533 | HIGH | 8.8 | — | Aug 11, 2026 | An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypas... |
| CVE-2026-50237 | HIGH | 7.4 | 0.2% | Aug 11, 2026 | A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace t... |
| CVE-2026-50236 | HIGH | 7.4 | 0.3% | Aug 11, 2026 | An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are... |
| CVE-2026-13739 | HIGH | 8.8 | — | Aug 11, 2026 | A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability relate... |
| CVE-2026-13738 | CRITICAL | 9.2 | — | Aug 11, 2026 | CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Soft... |
| CVE-2026-13737 | CRITICAL | 9.2 | — | Aug 11, 2026 | CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upg... |
| CVE-2026-58231 | CRITICAL | 10 | 0.7% | Aug 11, 2026 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially craf... |
| CVE-2026-73162 | MEDIUM | 5.3 | 0.2% | Aug 11, 2026 | Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /acco... |
| CVE-2026-33922 | MEDIUM | 6.8 | 0.2% | Aug 11, 2026 | A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to in... |
| CVE-2026-33921 | MEDIUM | 5.2 | 0.1% | Aug 11, 2026 | The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver ... |
| CVE-2026-73161 | MEDIUM | 5.1 | 0.2% | Aug 11, 2026 | Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feat... |
| CVE-2026-73160 | HIGH | 8.7 | — | Aug 11, 2026 | Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoi... |
| CVE-2026-73159 | MEDIUM | 5.1 | 0.2% | Aug 11, 2026 | Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's ... |
| CVE-2026-73158 | MEDIUM | 5.1 | 0.2% | Aug 11, 2026 | Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can cont... |
| CVE-2026-73157 | LOW | 2.3 | 0.3% | Aug 11, 2026 | Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface usi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now