2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81316 | LOW | 2.1 | 0.1% | Aug 30, 2026 | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over... |
| CVE-2026-80227 | LOW | 2.1 | 0.3% | Aug 30, 2026 | Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriag... |
| CVE-2026-78691 | LOW | 2.1 | 0.1% | Aug 30, 2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who s... |
| CVE-2026-82488 | LOW | 3.5 | 0.2% | Aug 30, 2026 | A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component Us... |
| CVE-2026-82483 | LOW | 3.5 | 0.2% | Aug 30, 2026 | A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown functi... |
| CVE-2026-82482 | LOW | 3.5 | 0.2% | Aug 30, 2026 | A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an ... |
| CVE-2026-78364 | LOW | 3.5 | 0.2% | Aug 30, 2026 | The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting th... |
| CVE-2026-77846 | LOW | 2.1 | 0.1% | Aug 30, 2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attack... |
| CVE-2026-82562 | LOW | 3.7 | 0.3% | Aug 30, 2026 | ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value un... |
| CVE-2026-77831 | LOW | 2.1 | 0.1% | Aug 30, 2026 | Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large arr... |
| CVE-2026-81200 | LOW | 2.7 | 0.2% | Aug 29, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order informa... |
| CVE-2026-77704 | LOW | 2.7 | 0.2% | Aug 29, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the req... |
| CVE-2026-55785 | LOW | 3.7 | 0.3% | Aug 28, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptograph... |
| CVE-2026-77063 | LOW | 3.7 | 0.2% | Aug 28, 2026 | multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter ... |
| CVE-2026-22056 | LOW | 2.3 | 0.2% | Aug 28, 2026 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are su... |
| CVE-2026-13735 | LOW | 3.7 | 0.2% | Aug 28, 2026 | Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_da... |
| CVE-2026-58616 | LOW | 3 | 0.2% | Aug 28, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft E... |
| CVE-2026-82112 | LOW | 3.5 | — | Aug 28, 2026 | A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src... |
| CVE-2026-58106 | LOW | 2 | 0.1% | Aug 28, 2026 | CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was fixed by replacing unchecked strcpy() with a bound... |
| CVE-2026-38093 | LOW | 3.3 | 0.1% | Aug 28, 2026 | file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22... |
| CVE-2026-82249 | LOW | 3.1 | — | Aug 28, 2026 | gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attacker... |
| CVE-2026-82238 | LOW | 3.1 | 0.3% | Aug 28, 2026 | filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to w... |
| CVE-2026-82237 | LOW | 3.1 | 0.3% | Aug 28, 2026 | filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cl... |
| CVE-2026-82236 | LOW | 3.1 | 0.4% | Aug 28, 2026 | File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes ano... |
| CVE-2026-52681 | LOW | 3.1 | 0.3% | Aug 28, 2026 | Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the acco... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now