2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48026 | HIGH | 8.7 | 0.2% | Aug 7, 2026 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of th... |
| CVE-2026-47249 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling... |
| CVE-2026-58262 | HIGH | 7.1 | 0.1% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification cou... |
| CVE-2026-48169 | HIGH | 8.8 | 0.3% | Aug 7, 2026 | PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization fa... |
| CVE-2026-45808 | HIGH | 7.1 | — | Aug 7, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide... |
| CVE-2026-66061 | HIGH | 7.1 | 0.1% | Aug 7, 2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS... |
| CVE-2026-66060 | HIGH | 7.1 | — | Aug 7, 2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Co... |
| CVE-2026-47664 | HIGH | 8.6 | 0.1% | Aug 7, 2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ... |
| CVE-2026-47663 | HIGH | 8.7 | 0.2% | Aug 7, 2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ... |
| CVE-2026-47662 | HIGH | 8.7 | — | Aug 7, 2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ... |
| CVE-2026-65819 | HIGH | 7.5 | 0.4% | Aug 7, 2026 | gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-con... |
| CVE-2026-62296 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11... |
| CVE-2026-62295 | HIGH | 7.5 | — | Aug 7, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11... |
| CVE-2026-48007 | HIGH | 8.6 | 0.2% | Aug 7, 2026 | Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to ... |
| CVE-2026-47661 | HIGH | 8.7 | 0.4% | Aug 7, 2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ... |
| CVE-2026-47660 | HIGH | 8.7 | — | Aug 7, 2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ... |
| CVE-2026-47659 | HIGH | 8.7 | 0.4% | Aug 7, 2026 | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ... |
| CVE-2026-15972 | HIGH | 7.5 | 0.4% | Aug 7, 2026 | Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of servi... |
| CVE-2026-71847 | HIGH | 8.7 | — | Aug 7, 2026 | Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consume... |
| CVE-2026-70561 | HIGH | 7.1 | 0.3% | Aug 7, 2026 | TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user,... |
| CVE-2026-48098 | HIGH | 7.3 | — | Aug 7, 2026 | NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers... |
| CVE-2026-48097 | HIGH | 7.8 | — | Aug 7, 2026 | NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers... |
| CVE-2026-19231 | HIGH | 7.3 | 0.3% | Aug 7, 2026 | A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects ... |
| CVE-2026-11430 | HIGH | 7.3 | — | Aug 7, 2026 | Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook featu... |
| CVE-2026-64638 | HIGH | 8.9 | — | Aug 7, 2026 | WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now