2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19207 | LOW | 2.4 | — | Aug 7, 2026 | A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some ... |
| CVE-2026-61477 | LOW | 2.3 | — | Aug 7, 2026 | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline ... |
| CVE-2026-49005 | LOW | 2.4 | 0.1% | Aug 7, 2026 | The root password hash of the device can be obtained through unencrypted information in the firmware. |
| CVE-2026-71438 | LOW | 2.4 | 0.2% | Aug 6, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 ... |
| CVE-2026-71326 | LOW | 2.1 | 0.4% | Aug 6, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth... |
| CVE-2026-64655 | LOW | 2.1 | 0.3% | Aug 6, 2026 | GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify builds the certificate S... |
| CVE-2026-64652 | LOW | 3.3 | 0.1% | Aug 6, 2026 | GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characte... |
| CVE-2026-48082 | LOW | 3.7 | 0.4% | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver... |
| CVE-2026-48074 | LOW | 2.7 | 0.3% | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver... |
| CVE-2026-19167 | LOW | 3.1 | 0.3% | Aug 6, 2026 | Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rende... |
| CVE-2026-19161 | LOW | 3.1 | 0.3% | Aug 6, 2026 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the ren... |
| CVE-2026-19160 | LOW | 3.1 | 0.3% | Aug 6, 2026 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the ren... |
| CVE-2026-19110 | LOW | 2.4 | 0.3% | Aug 6, 2026 | A vulnerability was determined in DataGear up to 5.0.0. The impacted element is the function HtmlTplDashboardWidgetHtmlR... |
| CVE-2026-19059 | LOW | 3.3 | 0.2% | Aug 6, 2026 | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metag... |
| CVE-2026-14225 | LOW | 2.7 | 0.2% | Aug 6, 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-re... |
| CVE-2026-15599 | LOW | 3.3 | — | Aug 6, 2026 | Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allow... |
| CVE-2026-18839 | LOW | 2.2 | — | Aug 5, 2026 | An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal ... |
| CVE-2026-70437 | LOW | 3.7 | 0.1% | Aug 5, 2026 | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison... |
| CVE-2026-70430 | LOW | 2.7 | 0.2% | Aug 5, 2026 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as pa... |
| CVE-2026-70600 | LOW | 3.1 | 0.1% | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,... |
| CVE-2026-70598 | LOW | 3.9 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10... |
| CVE-2026-12730 | LOW | 3.8 | 0.2% | Aug 5, 2026 | IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug... |
| CVE-2026-17578 | LOW | 2.3 | — | Aug 5, 2026 | Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D re... |
| CVE-2026-8029 | LOW | 3.9 | — | Aug 5, 2026 | The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements ... |
| CVE-2026-16993 | LOW | 3.7 | 0.1% | Aug 5, 2026 | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage direc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now