2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63623 | MEDIUM | 5.5 | — | Aug 10, 2026 | A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were tempora... |
| CVE-2026-56619 | MEDIUM | 5.4 | — | Aug 10, 2026 | HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and out... |
| CVE-2026-12624 | MEDIUM | 4.3 | 0.2% | Aug 10, 2026 | Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a tra... |
| CVE-2026-72726 | MEDIUM | 6.5 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated u... |
| CVE-2026-72725 | MEDIUM | 5.4 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previo... |
| CVE-2026-72724 | MEDIUM | 4.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c... |
| CVE-2026-72723 | MEDIUM | 5.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.ano... |
| CVE-2026-72722 | MEDIUM | 4.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_... |
| CVE-2026-72721 | MEDIUM | 5.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChec... |
| CVE-2026-72720 | MEDIUM | 6.4 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse... |
| CVE-2026-72719 | MEDIUM | 6.7 | — | Aug 10, 2026 | Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transf... |
| CVE-2026-56620 | MEDIUM | 4.3 | — | Aug 10, 2026 | HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error repor... |
| CVE-2026-72761 | MEDIUM | 6.9 | — | Aug 10, 2026 | The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses afte... |
| CVE-2026-72760 | MEDIUM | 5.3 | — | Aug 10, 2026 | Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. Whe... |
| CVE-2026-72759 | MEDIUM | 6.9 | — | Aug 10, 2026 | In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization... |
| CVE-2026-72751 | MEDIUM | 5.1 | — | Aug 10, 2026 | CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise... |
| CVE-2026-71959 | MEDIUM | 5.8 | — | Aug 10, 2026 | Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c... |
| CVE-2026-63105 | MEDIUM | 5.4 | — | Aug 10, 2026 | ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome... |
| CVE-2026-59112 | MEDIUM | 4.4 | — | Aug 10, 2026 | Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability ... |
| CVE-2026-18478 | MEDIUM | 5.1 | — | Aug 10, 2026 | Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrar... |
| CVE-2026-16742 | MEDIUM | 6.7 | — | Aug 10, 2026 | systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed... |
| CVE-2026-15060 | MEDIUM | 4.7 | — | Aug 10, 2026 | When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o... |
| CVE-2026-15059 | MEDIUM | 5.5 | — | Aug 10, 2026 | Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traver... |
| CVE-2026-6373 | MEDIUM | 6.5 | — | Aug 10, 2026 | Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow... |
| CVE-2026-19278 | MEDIUM | 6.8 | — | Aug 10, 2026 | A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now