2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81102 | LOW | 3.1 | 0.2% | Aug 27, 2026 | The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_serve... |
| CVE-2026-56651 | LOW | 2 | 0.2% | Aug 27, 2026 | Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application open... |
| CVE-2026-13416 | LOW | 3.5 | 0.1% | Aug 27, 2026 | The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming... |
| CVE-2026-21807 | LOW | 3.9 | 0.1% | Aug 26, 2026 | HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow... |
| CVE-2026-21809 | LOW | 3.9 | 0.1% | Aug 26, 2026 | HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when i... |
| CVE-2026-77573 | LOW | 3.5 | 0.1% | Aug 26, 2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.... |
| CVE-2026-77508 | LOW | 3.5 | 0.2% | Aug 26, 2026 | Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email ... |
| CVE-2026-56547 | LOW | 3.5 | 0.2% | Aug 26, 2026 | The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler ... |
| CVE-2026-47844 | LOW | 3.7 | 0.2% | Aug 26, 2026 | In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for ... |
| CVE-2026-47843 | LOW | 3.7 | 0.2% | Aug 26, 2026 | In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrect... |
| CVE-2026-54548 | LOW | 3.3 | 0.1% | Aug 26, 2026 | kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH... |
| CVE-2026-13480 | LOW | 3.1 | 0.2% | Aug 26, 2026 | The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/f... |
| CVE-2026-7487 | LOW | 3.5 | 0.2% | Aug 26, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3... |
| CVE-2026-58108 | LOW | 1.2 | 0.2% | Aug 26, 2026 | The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no jo... |
| CVE-2026-15366 | LOW | 2.4 | 0.2% | Aug 26, 2026 | A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly wi... |
| CVE-2026-15365 | LOW | 2.4 | 0.2% | Aug 26, 2026 | A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps ou... |
| CVE-2026-19220 | LOW | 3.7 | 0.2% | Aug 26, 2026 | The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network be... |
| CVE-2026-9805 | LOW | 2.7 | 0.1% | Aug 26, 2026 | SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size... |
| CVE-2026-80201 | LOW | 2 | 0.2% | Aug 26, 2026 | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call ... |
| CVE-2026-80199 | LOW | 3.7 | 0.2% | Aug 26, 2026 | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers t... |
| CVE-2026-79289 | LOW | 3.1 | 0.2% | Aug 25, 2026 | Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote ... |
| CVE-2026-79272 | LOW | 3.1 | 0.2% | Aug 25, 2026 | Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compro... |
| CVE-2026-79255 | LOW | 3.1 | 0.3% | Aug 25, 2026 | Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise... |
| CVE-2026-79228 | LOW | 3.1 | 0.3% | Aug 25, 2026 | Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr... |
| CVE-2026-79203 | LOW | 3.1 | 0.2% | Aug 25, 2026 | Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now