2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63650 | LOW | 2 | 0.2% | Aug 14, 2026 | OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the con... |
| CVE-2026-27871 | LOW | 2.9 | 0.2% | Aug 14, 2026 | Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic At... |
| CVE-2026-49263 | LOW | 2 | 0.1% | Aug 14, 2026 | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-cont... |
| CVE-2026-73844 | LOW | 3.7 | 0.2% | Aug 14, 2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream respon... |
| CVE-2026-47192 | LOW | 2.1 | 0.2% | Aug 14, 2026 | kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and pro... |
| CVE-2026-47191 | LOW | 2.1 | 0.2% | Aug 14, 2026 | kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or S... |
| CVE-2026-19841 | LOW | 3.1 | — | Aug 14, 2026 | A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of th... |
| CVE-2026-19837 | LOW | 2.7 | — | Aug 14, 2026 | A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/... |
| CVE-2026-19835 | LOW | 3.8 | — | Aug 14, 2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality... |
| CVE-2026-19763 | LOW | 3.8 | 0.4% | Aug 14, 2026 | A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory ... |
| CVE-2026-19749 | LOW | 3.7 | 0.4% | Aug 13, 2026 | A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20... |
| CVE-2026-19748 | LOW | 3.7 | 0.3% | Aug 13, 2026 | A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC... |
| CVE-2026-17071 | LOW | 2.7 | 0.3% | Aug 13, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traver... |
| CVE-2026-49096 | LOW | 3.5 | 0.3% | Aug 13, 2026 | Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malf... |
| CVE-2026-17043 | LOW | 3.8 | 0.4% | Aug 13, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal... |
| CVE-2026-58511 | LOW | 2.7 | 0.2% | Aug 13, 2026 | Webhook Authorization Header Returned in Plaintext via API |
| CVE-2026-58445 | LOW | 2.7 | 0.2% | Aug 13, 2026 | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API |
| CVE-2026-55984 | LOW | 2.7 | 0.3% | Aug 13, 2026 | Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service |
| CVE-2026-23603 | LOW | 3.1 | 0.2% | Aug 13, 2026 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim |
| CVE-2026-73575 | LOW | 3.5 | 0.1% | Aug 13, 2026 | In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange W... |
| CVE-2026-6469 | LOW | 3.8 | 0.2% | Aug 13, 2026 | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics ... |
| CVE-2026-16241 | LOW | 3.8 | 0.2% | Aug 13, 2026 | Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service again... |
| CVE-2026-14673 | LOW | 3.8 | 0.2% | Aug 13, 2026 | Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary ... |
| CVE-2026-14213 | LOW | 3.7 | 0.2% | Aug 13, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated em... |
| CVE-2026-48791 | LOW | 2 | 0.1% | Aug 13, 2026 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now