2026 CVE Vulnerabilities
43,253 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48766 | HIGH | 7.6 | 0.3% | Aug 11, 2026 | TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltr... |
| CVE-2026-48495 | HIGH | 7.1 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JS... |
| CVE-2026-42142 | HIGH | 7.1 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getShee... |
| CVE-2026-19546 | HIGH | 8.8 | — | Aug 11, 2026 | A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed S... |
| CVE-2026-18640 | HIGH | 7.1 | — | Aug 11, 2026 | The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT perm... |
| CVE-2026-18639 | HIGH | 7.3 | — | Aug 11, 2026 | When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, s... |
| CVE-2026-72922 | HIGH | 8.2 | — | Aug 11, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-72921 | HIGH | 8.1 | — | Aug 11, 2026 | SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth... |
| CVE-2026-18860 | HIGH | 8.7 | — | Aug 11, 2026 | Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can cr... |
| CVE-2026-18635 | HIGH | 7.2 | 0.3% | Aug 11, 2026 | Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able ... |
| CVE-2026-18129 | HIGH | 8.1 | — | Aug 11, 2026 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a ... |
| CVE-2026-18127 | HIGH | 7.7 | — | Aug 11, 2026 | External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentica... |
| CVE-2026-18125 | HIGH | 7.5 | — | Aug 11, 2026 | An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated at... |
| CVE-2026-51583 | HIGH | 8.5 | 0.2% | Aug 11, 2026 | An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF... |
| CVE-2026-19539 | HIGH | 8.6 | 0.3% | Aug 11, 2026 | Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5... |
| CVE-2026-72782 | HIGH | 7.1 | — | Aug 11, 2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secre... |
| CVE-2026-72781 | HIGH | 8.8 | — | Aug 11, 2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerabili... |
| CVE-2026-72780 | HIGH | 7.1 | — | Aug 11, 2026 | Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey ... |
| CVE-2026-72779 | HIGH | 8.7 | — | Aug 11, 2026 | Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create()... |
| CVE-2026-72778 | HIGH | 8.8 | — | Aug 11, 2026 | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex... |
| CVE-2026-72774 | HIGH | 7.1 | — | Aug 11, 2026 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenti... |
| CVE-2026-72772 | HIGH | 8.9 | — | Aug 11, 2026 | n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When... |
| CVE-2026-72771 | HIGH | 7.1 | — | Aug 11, 2026 | n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when ... |
| CVE-2026-72770 | HIGH | 7.1 | — | Aug 11, 2026 | n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operati... |
| CVE-2026-72767 | HIGH | 8.7 | — | Aug 11, 2026 | n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Gi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now