2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77351 | LOW | 3.5 | 0.2% | Aug 31, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authentic... |
| CVE-2026-82906 | LOW | 3.7 | 0.4% | Aug 31, 2026 | A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Contro... |
| CVE-2026-14367 | LOW | 3.1 | 0.1% | Aug 31, 2026 | The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_i... |
| CVE-2026-82810 | LOW | 3.3 | 0.1% | Aug 31, 2026 | A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is th... |
| CVE-2026-21827 | LOW | 3.1 | 0.2% | Aug 31, 2026 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in... |
| CVE-2026-82699 | LOW | 2.7 | — | Aug 31, 2026 | A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impact... |
| CVE-2026-82697 | LOW | 3.7 | — | Aug 31, 2026 | A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe5... |
| CVE-2026-82677 | LOW | 2.4 | — | Aug 31, 2026 | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/mo... |
| CVE-2026-82671 | LOW | 3.4 | 0.2% | Aug 31, 2026 | A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in... |
| CVE-2026-82863 | LOW | 3.3 | 0.1% | Aug 31, 2026 | @hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging... |
| CVE-2026-82665 | LOW | 3.8 | 0.4% | Aug 31, 2026 | A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the fi... |
| CVE-2026-82631 | LOW | 2.2 | 0.4% | Aug 31, 2026 | A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlocked... |
| CVE-2026-82622 | LOW | 3.5 | 0.2% | Aug 31, 2026 | A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown f... |
| CVE-2026-82727 | LOW | 2.3 | 0.3% | Aug 31, 2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire ... |
| CVE-2026-82725 | LOW | 2.3 | 0.3% | Aug 31, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls ... |
| CVE-2026-82681 | LOW | 2 | 0.3% | Aug 31, 2026 | Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's ... |
| CVE-2026-81853 | LOW | 2.3 | 0.3% | Aug 31, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into a... |
| CVE-2026-81852 | LOW | 2.1 | 0.3% | Aug 31, 2026 | Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, ... |
| CVE-2026-82596 | LOW | 3.3 | 0.1% | Aug 31, 2026 | A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDe... |
| CVE-2026-82367 | LOW | 2.3 | 0.2% | Aug 30, 2026 | Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolv... |
| CVE-2026-81643 | LOW | 2.3 | 0.2% | Aug 30, 2026 | Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a su... |
| CVE-2026-82555 | LOW | 3.7 | 0.4% | Aug 30, 2026 | A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAu... |
| CVE-2026-81322 | LOW | 2.1 | 0.1% | Aug 30, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with acc... |
| CVE-2026-82656 | LOW | 2.6 | 0.3% | Aug 30, 2026 | Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated user... |
| CVE-2026-81318 | LOW | 2.1 | 0.1% | Aug 30, 2026 | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now