2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17599 | MEDIUM | 6.9 | — | Aug 7, 2026 | Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. Th... |
| CVE-2026-17598 | MEDIUM | 5.3 | — | Aug 7, 2026 | Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when ... |
| CVE-2026-17597 | MEDIUM | 5.1 | — | Aug 7, 2026 | Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification f... |
| CVE-2026-17596 | MEDIUM | 6.3 | — | Aug 7, 2026 | Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:cre... |
| CVE-2026-17595 | MEDIUM | 5.3 | 0.3% | Aug 7, 2026 | Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select... |
| CVE-2026-66059 | MEDIUM | 5.3 | — | Aug 7, 2026 | Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass expose... |
| CVE-2026-62996 | MEDIUM | 6.9 | — | Aug 7, 2026 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From... |
| CVE-2026-62992 | MEDIUM | 6.9 | — | Aug 7, 2026 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio... |
| CVE-2026-48093 | MEDIUM | 6.5 | 0.2% | Aug 7, 2026 | The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the ex... |
| CVE-2026-19210 | MEDIUM | 6.3 | 0.3% | Aug 7, 2026 | A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of... |
| CVE-2026-37171 | MEDIUM | 5.9 | — | Aug 7, 2026 | A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one ... |
| CVE-2026-19206 | MEDIUM | 5.3 | 0.2% | Aug 7, 2026 | A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopT... |
| CVE-2026-16637 | MEDIUM | 6.5 | 0.2% | Aug 7, 2026 | OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlis... |
| CVE-2026-66838 | MEDIUM | 5.9 | — | Aug 7, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr... |
| CVE-2026-56794 | MEDIUM | 6.5 | — | Aug 7, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A lo... |
| CVE-2026-48094 | MEDIUM | 5.3 | — | Aug 7, 2026 | The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the abse... |
| CVE-2026-54217 | MEDIUM | 5.3 | — | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send ... |
| CVE-2026-54216 | MEDIUM | 5.3 | — | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By ... |
| CVE-2026-54215 | MEDIUM | 5.3 | — | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An atta... |
| CVE-2026-54214 | MEDIUM | 5.3 | — | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL par... |
| CVE-2026-54207 | MEDIUM | 6.3 | 0.5% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, whi... |
| CVE-2026-54206 | MEDIUM | 6.3 | 0.3% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, wh... |
| CVE-2026-54205 | MEDIUM | 6.3 | — | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname”... |
| CVE-2026-54201 | MEDIUM | 6.9 | 0.3% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these lo... |
| CVE-2026-54199 | MEDIUM | 5.3 | 0.3% | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the applic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now