2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47080 | LOW | 2.1 | 0.2% | Aug 21, 2026 | XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vu... |
| CVE-2026-47079 | LOW | 2.1 | 0.1% | Aug 21, 2026 | Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoof... |
| CVE-2026-66721 | LOW | 2.7 | 0.2% | Aug 21, 2026 | Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by def... |
| CVE-2026-19435 | LOW | 2.7 | 0.2% | Aug 21, 2026 | The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allo... |
| CVE-2026-19085 | LOW | 2.7 | 0.2% | Aug 21, 2026 | The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplic... |
| CVE-2026-16577 | LOW | 2.7 | 0.2% | Aug 21, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a c... |
| CVE-2026-14325 | LOW | 3.5 | 0.1% | Aug 21, 2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its set... |
| CVE-2026-76137 | LOW | 3.3 | 0.1% | Aug 21, 2026 | Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local... |
| CVE-2026-43679 | LOW | 2.4 | 0.1% | Aug 21, 2026 | This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physi... |
| CVE-2026-77648 | LOW | 2.2 | 0.2% | Aug 20, 2026 | In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allow... |
| CVE-2026-54505 | LOW | 2 | 0.4% | Aug 20, 2026 | TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unesca... |
| CVE-2026-49245 | LOW | 3.7 | 0.2% | Aug 20, 2026 | SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on bro... |
| CVE-2026-70652 | LOW | 2 | 0.1% | Aug 20, 2026 | libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahd... |
| CVE-2026-77151 | LOW | 3.7 | 0.3% | Aug 20, 2026 | A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of t... |
| CVE-2026-66788 | LOW | 3.7 | 0.2% | Aug 20, 2026 | A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where th... |
| CVE-2026-66785 | LOW | 2.5 | 0.1% | Aug 20, 2026 | A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from o... |
| CVE-2026-49996 | LOW | 3.7 | 0.2% | Aug 20, 2026 | SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se... |
| CVE-2026-64846 | LOW | 2.8 | 0.1% | Aug 20, 2026 | Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the rec... |
| CVE-2026-18283 | LOW | 2.4 | 0.2% | Aug 20, 2026 | Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attacker... |
| CVE-2026-18280 | LOW | 3.9 | 0.2% | Aug 20, 2026 | Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically presen... |
| CVE-2026-18278 | LOW | 3.5 | 0.2% | Aug 20, 2026 | Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows ... |
| CVE-2026-64963 | LOW | 2.3 | 0.4% | Aug 20, 2026 | A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when... |
| CVE-2026-7485 | LOW | 2.3 | 0.2% | Aug 20, 2026 | Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allo... |
| CVE-2026-73542 | LOW | 3.7 | 0.1% | Aug 20, 2026 | Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an at... |
| CVE-2026-19699 | LOW | 2.7 | 0.2% | Aug 20, 2026 | The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoint... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now