2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72606 | HIGH | 7.5 | — | Aug 11, 2026 | A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the ... |
| CVE-2026-72605 | HIGH | 7.5 | — | Aug 11, 2026 | A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary ... |
| CVE-2026-72602 | HIGH | 7.5 | — | Aug 11, 2026 | A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attacke... |
| CVE-2026-72601 | HIGH | 7.5 | — | Aug 11, 2026 | A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissi... |
| CVE-2026-72600 | HIGH | 7.5 | — | Aug 11, 2026 | A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download... |
| CVE-2026-72596 | HIGH | 8.1 | — | Aug 11, 2026 | A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete pos... |
| CVE-2026-72595 | HIGH | 8.1 | — | Aug 11, 2026 | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update tic... |
| CVE-2026-72563 | HIGH | 8.1 | — | Aug 11, 2026 | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite ... |
| CVE-2026-72562 | HIGH | 8.8 | — | Aug 11, 2026 | An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users... |
| CVE-2026-72561 | HIGH | 8.8 | — | Aug 11, 2026 | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-a... |
| CVE-2026-72558 | HIGH | 8.8 | — | Aug 11, 2026 | An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via... |
| CVE-2026-72557 | HIGH | 8.8 | — | Aug 11, 2026 | An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extensi... |
| CVE-2026-72556 | HIGH | 8.8 | — | Aug 11, 2026 | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by expl... |
| CVE-2026-72555 | HIGH | 8.1 | — | Aug 11, 2026 | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.role... |
| CVE-2026-72552 | HIGH | 7.5 | — | Aug 11, 2026 | A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the ... |
| CVE-2026-72551 | HIGH | 8.8 | — | Aug 11, 2026 | A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute... |
| CVE-2026-72548 | HIGH | 7.5 | — | Aug 11, 2026 | An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ... |
| CVE-2026-72547 | HIGH | 7.1 | — | Aug 11, 2026 | An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org... |
| CVE-2026-72546 | HIGH | 7.1 | — | Aug 11, 2026 | An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org... |
| CVE-2026-72545 | HIGH | 7.5 | — | Aug 11, 2026 | An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote ... |
| CVE-2026-72544 | HIGH | 7.5 | — | Aug 11, 2026 | An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ... |
| CVE-2026-72543 | HIGH | 7.5 | — | Aug 11, 2026 | An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote ... |
| CVE-2026-72538 | HIGH | 8.8 | — | Aug 11, 2026 | An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code... |
| CVE-2026-72537 | HIGH | 8.8 | — | Aug 11, 2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s... |
| CVE-2026-72536 | HIGH | 8.6 | — | Aug 11, 2026 | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mani... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now