2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-79777 | LOW | 2.7 | 0.2% | Aug 25, 2026 | rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger p... |
| CVE-2026-70548 | LOW | 3.5 | 0.2% | Aug 25, 2026 | Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External De... |
| CVE-2026-15310 | LOW | 2.1 | 0.3% | Aug 25, 2026 | When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controll... |
| CVE-2026-78887 | LOW | 3.7 | 0.3% | Aug 25, 2026 | A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of th... |
| CVE-2026-78886 | LOW | 3.7 | 0.4% | Aug 25, 2026 | A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/s... |
| CVE-2026-21758 | LOW | 3.7 | 0.2% | Aug 25, 2026 | HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive inf... |
| CVE-2026-66882 | LOW | 2.1 | 0.4% | Aug 25, 2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows... |
| CVE-2026-78638 | LOW | 3.3 | 0.1% | Aug 25, 2026 | A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dis... |
| CVE-2026-72701 | LOW | 3.7 | 0.2% | Aug 25, 2026 | Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string compar... |
| CVE-2026-16434 | LOW | 2.3 | 0.3% | Aug 25, 2026 | Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GH... |
| CVE-2026-78435 | LOW | 3.8 | 0.4% | Aug 24, 2026 | A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Contr... |
| CVE-2026-75554 | LOW | 2.3 | 0.2% | Aug 24, 2026 | Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from... |
| CVE-2026-76816 | LOW | 3.5 | 0.2% | Aug 24, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, ... |
| CVE-2026-78187 | LOW | 3.1 | 0.4% | Aug 24, 2026 | A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication... |
| CVE-2026-19565 | LOW | 3.7 | 0.4% | Aug 23, 2026 | Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock ... |
| CVE-2026-77003 | LOW | 2.7 | 0.2% | Aug 23, 2026 | The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being c... |
| CVE-2026-78049 | LOW | 3.7 | 0.4% | Aug 22, 2026 | A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVar... |
| CVE-2026-71514 | LOW | 3.3 | 0.1% | Aug 22, 2026 | NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the c... |
| CVE-2026-14187 | LOW | 2.7 | 0.2% | Aug 22, 2026 | The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, al... |
| CVE-2026-33333 | LOW | 3.5 | 0.2% | Aug 21, 2026 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the... |
| CVE-2026-48756 | LOW | 2.1 | 0.2% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBacku... |
| CVE-2026-48754 | LOW | 2.1 | 0.2% | Aug 21, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromB... |
| CVE-2026-18356 | LOW | 3.7 | 0.2% | Aug 21, 2026 | The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist ca... |
| CVE-2026-13176 | LOW | 2.7 | 0.2% | Aug 21, 2026 | The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify eve... |
| CVE-2026-48590 | LOW | 2.1 | 0.2% | Aug 21, 2026 | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now