2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-70622 | HIGH | 7.1 | — | Aug 10, 2026 | tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t... |
| CVE-2026-10754 | HIGH | 8.6 | 0.6% | Aug 10, 2026 | Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may ... |
| CVE-2026-72731 | HIGH | 7.1 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-l... |
| CVE-2026-72730 | HIGH | 8.7 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Edit... |
| CVE-2026-71576 | HIGH | 8.5 | 0.1% | Aug 10, 2026 | A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming ... |
| CVE-2026-72718 | HIGH | 7 | — | Aug 10, 2026 | goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system... |
| CVE-2026-66738 | HIGH | 8.8 | — | Aug 10, 2026 | SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint ... |
| CVE-2026-48048 | HIGH | 7.5 | — | Aug 10, 2026 | XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Sta... |
| CVE-2026-19433 | HIGH | 8.6 | — | Aug 10, 2026 | Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before ... |
| CVE-2026-72692 | HIGH | 7.5 | — | Aug 10, 2026 | A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote att... |
| CVE-2026-72691 | HIGH | 7.5 | — | Aug 10, 2026 | An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at... |
| CVE-2026-72690 | HIGH | 7.1 | — | Aug 10, 2026 | An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to i... |
| CVE-2026-72689 | HIGH | 7.5 | — | Aug 10, 2026 | A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticate... |
| CVE-2026-72688 | HIGH | 7.5 | — | Aug 10, 2026 | A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at... |
| CVE-2026-6374 | HIGH | 7.3 | — | Aug 10, 2026 | Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executab... |
| CVE-2026-59233 | HIGH | 8.7 | — | Aug 10, 2026 | Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authent... |
| CVE-2026-59090 | HIGH | 8.4 | 0.3% | Aug 10, 2026 | A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` ... |
| CVE-2026-12984 | HIGH | 8.2 | — | Aug 10, 2026 | Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. T... |
| CVE-2026-72594 | HIGH | 7.6 | — | Aug 10, 2026 | A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authentic... |
| CVE-2026-72591 | HIGH | 7.7 | — | Aug 10, 2026 | A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make t... |
| CVE-2026-72586 | HIGH | 7.5 | — | Aug 10, 2026 | A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to que... |
| CVE-2026-72584 | HIGH | 7.4 | — | Aug 10, 2026 | A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attac... |
| CVE-2026-72582 | HIGH | 7.5 | — | Aug 10, 2026 | A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to cras... |
| CVE-2026-72581 | HIGH | 8.6 | — | Aug 10, 2026 | A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker... |
| CVE-2026-72579 | HIGH | 7.5 | — | Aug 10, 2026 | An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now