2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42393 | LOW | 3.1 | 0.1% | Aug 28, 2026 | The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the confi... |
| CVE-2026-40204 | LOW | 3.1 | 0.2% | Aug 28, 2026 | None None None No publicly available exploits are known. |
| CVE-2026-40203 | LOW | 3.7 | 0.2% | Aug 28, 2026 | When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes ... |
| CVE-2026-79615 | LOW | 2.7 | 0.1% | Aug 28, 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question ba... |
| CVE-2026-81848 | LOW | 3.5 | 0.2% | Aug 28, 2026 | A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fe... |
| CVE-2026-81836 | LOW | 3.7 | 0.2% | Aug 28, 2026 | A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file sr... |
| CVE-2026-59314 | LOW | 3.7 | 0.2% | Aug 27, 2026 | Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response split... |
| CVE-2026-59306 | LOW | 3.8 | 0.2% | Aug 27, 2026 | Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud ... |
| CVE-2026-59305 | LOW | 3.8 | 0.1% | Aug 27, 2026 | Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stre... |
| CVE-2026-59304 | LOW | 3.8 | 0.1% | Aug 27, 2026 | Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Clou... |
| CVE-2026-59303 | LOW | 3.8 | 0.1% | Aug 27, 2026 | Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cl... |
| CVE-2026-59300 | LOW | 3.5 | 0.1% | Aug 27, 2026 | Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Func... |
| CVE-2026-59299 | LOW | 3.5 | 0.1% | Aug 27, 2026 | Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Sp... |
| CVE-2026-59298 | LOW | 3.5 | 0.2% | Aug 27, 2026 | Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cl... |
| CVE-2026-59297 | LOW | 3.5 | 0.1% | Aug 27, 2026 | Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Functi... |
| CVE-2026-59292 | LOW | 3.2 | 0.1% | Aug 27, 2026 | PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdi... |
| CVE-2026-54713 | LOW | 3.7 | 0.4% | Aug 27, 2026 | CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() gener... |
| CVE-2026-81725 | LOW | 3.7 | 0.2% | Aug 27, 2026 | NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attac... |
| CVE-2026-81723 | LOW | 3.7 | 0.4% | Aug 27, 2026 | NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that ... |
| CVE-2026-81717 | LOW | 3.5 | 0.1% | Aug 27, 2026 | openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, wh... |
| CVE-2026-81715 | LOW | 3.3 | 0.2% | Aug 27, 2026 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the p... |
| CVE-2026-81696 | LOW | 3.3 | 0.2% | Aug 27, 2026 | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info ... |
| CVE-2026-81695 | LOW | 3.3 | 0.2% | Aug 27, 2026 | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt ... |
| CVE-2026-81694 | LOW | 3.3 | 0.2% | Aug 27, 2026 | openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the... |
| CVE-2026-81685 | LOW | 3.3 | 0.2% | Aug 27, 2026 | openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now