2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16558 | MEDIUM | 5.4 | 0.2% | Aug 8, 2026 | The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it... |
| CVE-2026-16535 | MEDIUM | 6.1 | 0.2% | Aug 8, 2026 | The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a r... |
| CVE-2026-16282 | MEDIUM | 5.3 | 0.1% | Aug 8, 2026 | The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against t... |
| CVE-2026-16269 | MEDIUM | 4.8 | 0.2% | Aug 8, 2026 | The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica... |
| CVE-2026-18988 | MEDIUM | 6.4 | 0.3% | Aug 8, 2026 | The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block a... |
| CVE-2026-49343 | MEDIUM | 5.9 | — | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie... |
| CVE-2026-48122 | MEDIUM | 5.4 | 0.1% | Aug 7, 2026 | Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP... |
| CVE-2026-48047 | MEDIUM | 5.9 | 0.3% | Aug 7, 2026 | XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to ... |
| CVE-2026-47127 | MEDIUM | 6.5 | — | Aug 7, 2026 | Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR... |
| CVE-2026-64676 | MEDIUM | 5.7 | — | Aug 7, 2026 | Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In ... |
| CVE-2026-46405 | MEDIUM | 5.3 | — | Aug 7, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth m... |
| CVE-2026-11743 | MEDIUM | 6.6 | 0.1% | Aug 7, 2026 | The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length o... |
| CVE-2026-9031 | MEDIUM | 6.8 | 0.2% | Aug 7, 2026 | An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied da... |
| CVE-2026-9030 | MEDIUM | 6.8 | 0.1% | Aug 7, 2026 | A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction han... |
| CVE-2026-71381 | MEDIUM | 4 | 0.2% | Aug 7, 2026 | Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a... |
| CVE-2026-69207 | MEDIUM | 5.3 | 0.7% | Aug 7, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in COR... |
| CVE-2026-59717 | MEDIUM | 4.3 | — | Aug 7, 2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Andr... |
| CVE-2026-54338 | MEDIUM | 5.3 | 0.3% | Aug 7, 2026 | JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid in... |
| CVE-2026-46358 | MEDIUM | 5.4 | 0.1% | Aug 7, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functi... |
| CVE-2026-19246 | MEDIUM | 6.3 | 0.2% | Aug 7, 2026 | A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the f... |
| CVE-2026-19244 | MEDIUM | 4.7 | 0.3% | Aug 7, 2026 | A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of t... |
| CVE-2026-11425 | MEDIUM | 4.4 | — | Aug 7, 2026 | Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allo... |
| CVE-2026-71870 | MEDIUM | 4.8 | 0.1% | Aug 7, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumpti... |
| CVE-2026-66151 | MEDIUM | 5.5 | 0.2% | Aug 7, 2026 | SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the ... |
| CVE-2026-62293 | MEDIUM | 5 | — | Aug 7, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now