2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18370 | MEDIUM | 4.8 | — | Aug 10, 2026 | entr is vulnerable to Heap-based buffer overflow in run_utility() function. The function allocates a fixed-size heap buf... |
| CVE-2026-59088 | MEDIUM | 5.5 | — | Aug 10, 2026 | A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI im... |
| CVE-2026-72588 | MEDIUM | 5.3 | — | Aug 10, 2026 | A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to d... |
| CVE-2026-72587 | MEDIUM | 6.1 | — | Aug 10, 2026 | A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison... |
| CVE-2026-72585 | MEDIUM | 6.5 | — | Aug 10, 2026 | An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact p... |
| CVE-2026-72583 | MEDIUM | 5.4 | — | Aug 10, 2026 | A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us... |
| CVE-2026-72576 | MEDIUM | 5.4 | — | Aug 10, 2026 | A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Autho... |
| CVE-2026-72574 | MEDIUM | 6.1 | — | Aug 10, 2026 | A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control... |
| CVE-2026-72570 | MEDIUM | 5.4 | — | Aug 10, 2026 | A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to injec... |
| CVE-2026-71394 | MEDIUM | 5.3 | — | Aug 10, 2026 | GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to a... |
| CVE-2026-71393 | MEDIUM | 5.3 | — | Aug 10, 2026 | GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function compute... |
| CVE-2026-71392 | MEDIUM | 5.3 | — | Aug 10, 2026 | GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. Whe... |
| CVE-2026-71391 | MEDIUM | 5.3 | — | Aug 10, 2026 | GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index b... |
| CVE-2026-66642 | MEDIUM | 5.4 | 0.1% | Aug 10, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP... |
| CVE-2026-66486 | MEDIUM | 4.6 | — | Aug 10, 2026 | GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When list... |
| CVE-2026-66485 | MEDIUM | 4.6 | — | Aug 10, 2026 | GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function us... |
| CVE-2026-66484 | MEDIUM | 4.6 | — | Aug 10, 2026 | GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar arch... |
| CVE-2026-65945 | MEDIUM | 6.5 | 0.3% | Aug 10, 2026 | Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0,... |
| CVE-2026-19404 | MEDIUM | 6.5 | 0.4% | Aug 10, 2026 | A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operati... |
| CVE-2026-66411 | MEDIUM | 6.9 | — | Aug 10, 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unaut... |
| CVE-2026-66410 | MEDIUM | 4.8 | — | Aug 10, 2026 | Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or alt... |
| CVE-2026-66409 | MEDIUM | 6.9 | 0.3% | Aug 10, 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password ma... |
| CVE-2026-66408 | MEDIUM | 5.1 | 0.2% | Aug 10, 2026 | The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affec... |
| CVE-2026-66406 | MEDIUM | 4.8 | 0.2% | Aug 10, 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle at... |
| CVE-2026-66404 | MEDIUM | 6.5 | 0.2% | Aug 10, 2026 | DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now