2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6426 | MEDIUM | 4.4 | 0.2% | Aug 10, 2026 | A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size... |
| CVE-2026-73035 | MEDIUM | 5.3 | 0.2% | Aug 10, 2026 | npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t... |
| CVE-2026-72912 | MEDIUM | 4.3 | — | Aug 10, 2026 | CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec... |
| CVE-2026-72908 | MEDIUM | 6.5 | — | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template... |
| CVE-2026-72907 | MEDIUM | 6.5 | — | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function ... |
| CVE-2026-72906 | MEDIUM | 4.3 | 0.2% | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email ... |
| CVE-2026-72743 | MEDIUM | 5.4 | — | Aug 10, 2026 | SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb... |
| CVE-2026-18942 | MEDIUM | 5.5 | 0.3% | Aug 10, 2026 | A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th... |
| CVE-2026-16456 | MEDIUM | 6.5 | 0.3% | Aug 10, 2026 | A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex... |
| CVE-2026-72881 | MEDIUM | 6.4 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command bui... |
| CVE-2026-72873 | MEDIUM | 6.5 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/... |
| CVE-2026-69116 | MEDIUM | 6.1 | 0.2% | Aug 10, 2026 | FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives.... |
| CVE-2026-44401 | MEDIUM | 4.8 | 0.2% | Aug 10, 2026 | Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that ... |
| CVE-2026-71968 | MEDIUM | 6.7 | — | Aug 10, 2026 | OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo... |
| CVE-2026-71967 | MEDIUM | 5.7 | — | Aug 10, 2026 | OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pse... |
| CVE-2026-6791 | MEDIUM | 6.6 | 0.2% | Aug 10, 2026 | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the ... |
| CVE-2026-68872 | MEDIUM | 6.5 | 0.2% | Aug 10, 2026 | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team... |
| CVE-2026-68871 | MEDIUM | 6.5 | 0.1% | Aug 10, 2026 | The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id ... |
| CVE-2026-68870 | MEDIUM | 5.3 | 0.1% | Aug 10, 2026 | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va... |
| CVE-2026-12339 | MEDIUM | 6.9 | 0.3% | Aug 10, 2026 | A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive contai... |
| CVE-2026-72739 | MEDIUM | 6.5 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs... |
| CVE-2026-72732 | MEDIUM | 4.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp... |
| CVE-2026-72728 | MEDIUM | 6.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed ... |
| CVE-2026-72727 | MEDIUM | 4.8 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged us... |
| CVE-2026-71577 | MEDIUM | 6.3 | — | Aug 10, 2026 | A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now