2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18611 | HIGH | 7.5 | 0.4% | Aug 10, 2026 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive... |
| CVE-2026-18608 | HIGH | 8.7 | 0.4% | Aug 10, 2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permission... |
| CVE-2026-15581 | HIGH | 8 | 0.2% | Aug 10, 2026 | A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to b... |
| CVE-2026-15467 | HIGH | 8.1 | 0.4% | Aug 10, 2026 | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can e... |
| CVE-2026-13717 | HIGH | 8.8 | 0.3% | Aug 10, 2026 | A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serv... |
| CVE-2026-11810 | HIGH | 7.5 | 0.3% | Aug 10, 2026 | The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) pars... |
| CVE-2026-72884 | HIGH | 8.7 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/... |
| CVE-2026-72883 | HIGH | 8.8 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/... |
| CVE-2026-72875 | HIGH | 8.8 | 0.5% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokplo... |
| CVE-2026-72874 | HIGH | 8.7 | 0.4% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/s... |
| CVE-2026-71966 | HIGH | 8.8 | — | Aug 10, 2026 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backu... |
| CVE-2026-71965 | HIGH | 8.8 | 0.3% | Aug 10, 2026 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote b... |
| CVE-2026-69118 | HIGH | 8.8 | 0.6% | Aug 10, 2026 | Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows ... |
| CVE-2026-69114 | HIGH | 7.1 | 0.3% | Aug 10, 2026 | Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b... |
| CVE-2026-69112 | HIGH | 7.1 | 0.1% | Aug 10, 2026 | Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec... |
| CVE-2026-14886 | HIGH | 8.2 | 0.2% | Aug 10, 2026 | Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma... |
| CVE-2026-72871 | HIGH | 7.5 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith... |
| CVE-2026-72870 | HIGH | 8.7 | 0.3% | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in pac... |
| CVE-2026-72866 | HIGH | 8.8 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/s... |
| CVE-2026-71969 | HIGH | 8.4 | — | Aug 10, 2026 | OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a... |
| CVE-2026-71964 | HIGH | 7.1 | 0.3% | Aug 10, 2026 | CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t... |
| CVE-2026-71962 | HIGH | 7.5 | — | Aug 10, 2026 | Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants... |
| CVE-2026-59091 | HIGH | 7.3 | 0.2% | Aug 10, 2026 | A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit t... |
| CVE-2026-72900 | HIGH | 7.1 | — | Aug 10, 2026 | Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. |
| CVE-2026-72734 | HIGH | 8.4 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutatio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now