2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18702 | MEDIUM | 6.4 | — | Aug 11, 2026 | An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnost... |
| CVE-2026-18701 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server ... |
| CVE-2026-18700 | MEDIUM | 6.5 | — | Aug 11, 2026 | An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an i... |
| CVE-2026-18699 | MEDIUM | 6.5 | — | Aug 11, 2026 | An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser... |
| CVE-2026-18698 | MEDIUM | 5.4 | — | Aug 11, 2026 | An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag... |
| CVE-2026-18697 | HIGH | 8.7 | — | Aug 11, 2026 | An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce... |
| CVE-2026-18696 | HIGH | 7 | — | Aug 11, 2026 | An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to ... |
| CVE-2026-18695 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could... |
| CVE-2026-18694 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus... |
| CVE-2026-18693 | HIGH | 7.6 | — | Aug 11, 2026 | An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges ... |
| CVE-2026-18692 | HIGH | 8.8 | — | Aug 11, 2026 | An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privil... |
| CVE-2026-18691 | CRITICAL | 9 | — | Aug 11, 2026 | An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influenc... |
| CVE-2026-18690 | HIGH | 8.1 | — | Aug 11, 2026 | An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag... |
| CVE-2026-18688 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory ... |
| CVE-2026-18687 | HIGH | 7.1 | — | Aug 11, 2026 | MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para... |
| CVE-2026-15426 | HIGH | 8.8 | 0.4% | Aug 11, 2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v... |
| CVE-2026-73219 | MEDIUM | 5.3 | — | Aug 11, 2026 | CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user... |
| CVE-2026-73218 | HIGH | 7.7 | — | Aug 11, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in A... |
| CVE-2026-73217 | HIGH | 7.7 | — | Aug 11, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in A... |
| CVE-2026-73216 | MEDIUM | 6.5 | — | Aug 11, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in sr... |
| CVE-2026-73215 | HIGH | 7.1 | — | Aug 11, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/a... |
| CVE-2026-73214 | HIGH | 8.2 | — | Aug 11, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and cr... |
| CVE-2026-73213 | MEDIUM | 5.8 | — | Aug 11, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_tu... |
| CVE-2026-73212 | MEDIUM | 5.8 | — | Aug 11, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_... |
| CVE-2026-73211 | CRITICAL | 9.8 | — | Aug 11, 2026 | PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now